|
|
|  |
|
|
|
|
F-Secure Malware Information Pages: Trojan-Downloader:W32/Small.HSG

|
|
|
| Radar |
 |
|
|
|
Summary
|
Trojan-Downloader:W32/Small.HSG downloads and runs a file that is detected as Trojan-Downloader.Win32.Agent.HQL.
This normally arrives as a dropped file by other malware or is downloaded unsuspectingly by the user from a malicious website. |
|
|
|
Detailed Description
|
Once running on the system, this trojan will download a file from the following website:
- http://ymq.a2000150.wrs.mcboo.com/[Removed]
The downloaded file will then be stored as:
- %Windows%\17PHolmes2000150.exe
It will be automatically executed from the infected machine without the users knowledge and will create a registry entry that will reference to the aforementioned location. This in turn will download and execute another trojan and will further compromise system security. |
|
|
|
F-Secure Corporation |
|
|
|
|
|
Last Modified: January 23, 2008
|
|
|
|
|