Home / malwarePDF  

Trojan-Downloader:W32/Small.CZL


First posted on 15 June 2007.
Source: SecurityHome

Aliases :

Trojan-Downloader:W32/Small.CZL is also known as Trojan.Spy.Agent.NDY, Small.czl, Trojan-Downloader.Win32.Small.czl.

Explanation :

Trojan-Downloader:W32/Small.CZL steals passwords and downloads files from several websites and executes them.

Trojan-Downloader:W32/Small.CZL is a trojan used to steal passwords from QQ Instant Messenger and also tries to download other components from the Internet. It may arrive on the system as a component of other malware or maybe downloaded from the Internet directly.

Upon execution, it drops the following files:


This trojan checks for the installation of the Chinese Instant Messenger QQ in the system by searching for the following registry entry:


Note: TyePath contains the path where the QQ.exe file is located, usually %ProgramFiles%TencentQQ.

If the QQ Instant Messenger is installed, it will search for the following file from the QQ installation path:


When this file is found, this trojan will rename the original TIMPLATFORM.EXE to TIMPLATFROM.EXE. After that, it will create a copy of itself with the name TIMPLATFORM.EXE.

It creates the following autostart registry entry:


It also sets the value of the following registry entry as part of its installation routine:

Trojan-Downloader:W32/Small.CZL also tries to delete the following file:


It also deletes the following registry key:


In order to steal passwords from QQ Instant Messenger, this trojan monitors the window used by QQ.exe and logs keystrokes.

This trojan may also download other components from the Internet.

Last update 15 June 2007

 

TOP

Malware :

Family: