Home / malwarePDF  

Trojan:W32/Tiny.E


First posted on 25 June 2008.
Source: SecurityHome

Aliases :

There are no other names known for Trojan:W32/Tiny.E.

Explanation :

Tiny.E spawns Explorer.exe and creates launch points in the system.

right]Tiny.E creates a winlogon launch point and runkey.

It modifies the following key:

  • HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogon
    Userinit=C:WINDOWSsystem32userinit.exe

The modification is as follows:

  • Userinit=C:WINDOWSsystem32userinit.exe, explorer.exe

Tiny.E creates the following key:

  • HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun
    Barsaka=explorer.exe

Last update 25 June 2008

 

TOP