BitDefender Antivirus

Trojan.Downloader.Small.FS

( Win32/TrojanDownloader.Small.J, TR/Dldr.Small.fz, MalwareScope.Downloader.Small.5 )
Spreading: very low
Damage: very low
Size: 110,592 bytes
Discovered: 2006 Dec 14

SYMPTOMS:

The trojan tries to connect to the Internet and download a file, wich will be placed in C:\dialler.exe.

TECHNICAL DESCRIPTION:

It makes the following HTTP reguest:
  • http://www.[REMOVED].com/cmb_220584.exe
The downloaded file will be placed in C:\dialler.exe, and then it will be run.

BitDefender was able to detect this file without any signature, as BehavesLike:Trojan.Downloader.

It does not represent a threat anymore, because the site where it tries to download the file has been closed.

This trojan has been named as Downloader.Small because the executable code from the file has about 1500 bytes, but the file has been padded with a lot of zeros, and it's size has been increased to over 100KB.

Removal instructions:

Please let BitDefender disinfect your files.

ANALYZED BY:

Raul Tosa, virus researcher