Additional Details
Trojan:W32/Tiny.E launches the explorer.exe process and modifies the Windows Registry to create launch points in the system.
On execution, the trojan modifies the following registry key:
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit=C:\WINDOWS\system32\userinit.exe
The modification is as follows:
- Userinit=C:\WINDOWS\system32\userinit.exe, explorer.exe
Tiny.E also creates the following key:
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Barsaka=explorer.exe