TROJ_SMALL.NSZ
Windows 98, ME, NT, 2000, XP, Server 2003

Threat Type: Trojan
Destructiveness: No
Encrypted: No
In the wild: Yes
OVERVIEW
This Trojan may be downloaded by other malware/grayware from remote sites.
TECHNICAL DETAILS
Varies
Yes
12 Jun 2010
Downloads files
Arrival Details
This Trojan may be downloaded by the following malware/grayware from remote sites:
- HTML_SHELLLOAD.B
It may be unknowingly downloaded by a user while visiting the following malicious websites:
- http://2677.in/log.exe
Installation
This Trojan drops the following component file(s):
- %User Profile%\Microsoft\smx4pnp.dll
(Note: %User Profile% is the current user's profile folder, which is usually C:\Windows\Profiles\{user name} on Windows 98 and ME, C:\WINNT\Profiles\{user name} on Windows NT, and C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003.)
Autostart Technique
This Trojan adds the following registry entries to enable its automatic execution at every system startup:
HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
smx4pnp = rundll32.exe "%User Profile%\Microsoft\smx4pnp.dll", Launch
Download Routine
This Trojan accesses the following websites to download files:
- http://d.iamcome.in/u.txt
SOLUTION
8.900
Step 1
For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you to allow full scanning of your computer.
Step 2
Remove malware files dropped/downloaded by TROJ_SMALL.NSZ