Win32/TrojanDownloader.Small.AAD [Threat Name] go to Threat

Win32/TrojanDownloader.Small.AAD [Threat Variant Name]

Category trojan
Size 16384 B
Detection created Aug 02, 2006
Detection database version 0.11688
Aliases Trojan.Win32.Pincav.cnyo (Kaspersky)
  Trojan.DownLoader10.30582 (Dr.Web)
  Troj/Agent-ADTS (Sophos)
Short description

Win32/TrojanDownloader.Small.AAD is a trojan which tries to download other malware from the Internet.

Installation

The trojan does not create any copies of itself.


The trojan creates and runs a new thread with its own program code within the following processes:

  • explorer.exe
Other information

The trojan contains a list of (2) URLs.


It tries to download a file from the addresses.


The files are stored in the following locations:

  • %currentfolder%\­over
  • ..\­%variable%

The files are then executed. The HTTP protocol is used.


A string with variable content is used instead of %variable% .


Trojan can detect presence of debuggers and other analytical tools.


The trojan quits immediately if it is run within a debugger.

Please enable Javascript to ensure correct displaying of this content and refresh this page.