Threat Description



Category: Malware
Type: Trojan-Dropper
Platform: W32
Aliases: Small.QP


Small.QP copies itself to the Windows folder and attempts to download and install other malware to the system.


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More scanning & removal options

More information on scanning or removal options is available in the documentation for your F-Secure security product on the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

For further assistance, F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.

Technical Details

Upon execution, this malware creates the mutex _Win_Loader_ to ensure that only one instance of itself is running in memory.Additionally, it drops the following files in the affected system:

  • %windir%\winlogon32.exe - A copy of itself (Detected as Trojan-Dropper.Win32.Small.qp)
  • %windir%\winlogon32.dll - Another malware file (Detected as Trojan-Downloader.Win32.Small.anj)
  • %windir%\prefoct.dat - An empty file

As a stealth mechanism, it loads the dropped DLL, winlogon32.dll, under the legitimate process: lsass.exe.Trojan-Downloader.Win32.Small.anj, on the other hand, creates the mutex _Win_Loader__Win_Loader_. This malware attempts to connect to the following web sites to possibly download other malicious components:

  •[REMOVED].php?i=21 Data downloaded is saved in the file, %windir%\prefoct.dat
  •[REMOVED].dat Data downloaded is saved in the file, %wndir%\_tmp0232.exe

Small.QP then executes the downloaded file, _tmp0232.exe. Note: Both download sites are unavailable at the time of writing.There are additional details on Small.QP on F-Secure's Weblog.


Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More