Threat Database Trojans Trojan.Small.D

Trojan.Small.D

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 7,557
Threat Level: 80 % (High)
Infected Computers: 1,140
First Seen: July 24, 2009
Last Seen: July 14, 2026
OS(es) Affected: Windows

The detection of Trojan.Small.D on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and take steps to remove it.

What Is Trojan.Small.D?

Trojan.Small.D is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate or harmless. The name "Trojan" refers to the malware's ability to deceive users into installing or executing it, often by masquerading as a useful program or file. The ".Small.D" designation suggests that this particular variant is relatively small in size and may be designed to evade detection by traditional antivirus software.

How Trojan.Small.D Operates

Once installed, Trojan.Small.D can operate in various ways, depending on its intended purpose. It may attempt to connect to a remote server to receive instructions or transmit stolen data, such as login credentials, credit card numbers, or sensitive personal information. It can also install additional malware, create backdoors for unauthorized access, or modify system settings to disable security features. The malware may also attempt to hide its presence by disguising itself as a system process or legitimate program.

Symptoms of Infection

Identifying a Trojan.Small.D infection can be challenging, as it may not exhibit obvious symptoms. However, some common signs of infection include slow system performance, frequent crashes, or unusual network activity. You may also notice unfamiliar programs or icons on your desktop, or receive unexpected pop-ups or alerts. In some cases, the malware may attempt to disable your antivirus software or prevent you from accessing certain websites or system features.

  • Unexplained changes to system settings or configuration
  • Appearance of unfamiliar programs or icons
  • Slow system performance or frequent crashes
  • Unusual network activity or unexpected pop-ups

How to Remove Trojan.Small.D

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will help you download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware. Be cautious when uninstalling programs, as some may be legitimate or required by your system.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Small.D from your system requires a combination of technical expertise and caution. By following the steps outlined above and using reputable anti-malware tools, you can help ensure the removal of this malicious software and prevent future infections. It's essential to remain vigilant and take proactive measures to protect your system, including keeping your operating system and software up-to-date, using strong antivirus software, and avoiding suspicious downloads or links.

Aliases

3 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Sophos Mal/Heuri-D
Panda Suspicious file
F-Secure Backdoor.Win32.Small.dmp

Analysis Report

General information

Family Name: Trojan.Small.D
Signature status: No Signature

Known Samples

MD5: 899776efe32524fa53266752ece53f3e
SHA1: d9518160b5182d5558dd92ad5c2fef0b59e8a398
SHA256: D95C422DF7DA6BE09F09578F9C9F3E5593C0B9CC71E7B271727C8E534ABE16AE
File Size: 69.71 KB, 69714 bytes
MD5: e3315eac4969ebd33dd8c40e43f73ff0
SHA1: 0dd2621e4808d6af686656e0b97b6ef929c42222
SHA256: 080222DCF80AAF64B7B58A0B1511B9914A15ADACCA663D6B2BA87FBE995C2595
File Size: 89.74 KB, 89739 bytes
MD5: d6b7f04a4f75b3361660771adba761fc
SHA1: 193d02b0f5357de5c08df60210ac471d44570b0a
SHA256: 116712EB507230E45BDFB98A595E728B6D86C912CE4F048931EED2AE52DEF611
File Size: 89.10 KB, 89101 bytes
MD5: 8498a38e6fa8887355c813f6176c38dd
SHA1: a8e792543157c0064bc50395b55ad8ea742c882f
SHA256: 0A004E4D355656E0BFBC156ACD0A91A546A6FADEA2769BBBF022879AB083F01A
File Size: 89.26 KB, 89257 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • 2+ executable sections
  • No Version Info
  • packed
  • x86

Block Information

Total Blocks: 170
Potentially Malicious Blocks: 127
Whitelisted Blocks: 43
Unknown Blocks: 0

Visual Map

x x x x x x x x 0 0 x x x x x x x x x x x x x x x x 0 x x 0 0 0 x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x 0 0 x x x x x x 0 0 0 0 0 x x x 0 0 x x x x x x x x x x x 0 x x x x x x x x x 0 x x x 0 x x x x 0 x x x x x x x x x x 0 0 x x x 0 x 0 0 x x x x x x x x x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Small.D

Files Modified

File Attributes
c:\windows\ouwininit.exe Generic Write,Read Attributes
c:\windows\syswow64\wbcal.exe Generic Write,Read Attributes
c:\windows\syswow64\wbuxx.exe Generic Write,Read Attributes
c:\windows\syswow64\wfsajo.exe Generic Write,Read Attributes
c:\windows\syswow64\wfyoduu.exe Generic Write,Read Attributes
c:\windows\syswow64\wgppfa.exe Generic Write,Read Attributes
c:\windows\syswow64\wjyk.exe Generic Write,Read Attributes
c:\windows\syswow64\wnwk.exe Generic Write,Read Attributes
c:\windows\syswow64\wpblurq.exe Generic Write,Read Attributes
c:\windows\syswow64\wrmhvxr.exe Generic Write,Read Attributes
Show More
c:\windows\syswow64\wvjtph.exe Generic Write,Read Attributes
c:\windows\syswow64\wwddnu.exe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��  xy* �/��Y�d�kP~� ��ރ�p-��^�o�eeaVs}EkP~E��1B��7 ���ﺃePe���"D��1T��fe��g� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 㕳ǜ RegNtPreCreateKey
HKLM\software\classes\typelib\{1ea4dbf0-3c3b-11cf-810c-00aa00389b71}\1.1\0\win32:: C:\WINDOWS\SysWow64\Oleacc.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{618736e0-3c3d-11cf-810c-00aa00389b71}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{618736e0-3c3d-11cf-810c-00aa00389b71}\typelib:: {1EA4DBF0-3C3B-11CF-810C-00AA00389B71} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{618736e0-3c3d-11cf-810c-00aa00389b71}\typelib::version 1.1 RegNtPreCreateKey
Show More
HKLM\software\classes\interface\{618736e0-3c3d-11cf-810c-00aa00389b71}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{618736e0-3c3d-11cf-810c-00aa00389b71}\typelib:: {1EA4DBF0-3C3B-11CF-810C-00AA00389B71} RegNtPreCreateKey
HKLM\software\classes\interface\{618736e0-3c3d-11cf-810c-00aa00389b71}\typelib::version 1.1 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{03022430-abc4-11d0-bde2-00aa001a1953}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{03022430-abc4-11d0-bde2-00aa001a1953}\typelib:: {1EA4DBF0-3C3B-11CF-810C-00AA00389B71} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{03022430-abc4-11d0-bde2-00aa001a1953}\typelib::version 1.1 RegNtPreCreateKey
HKLM\software\classes\interface\{03022430-abc4-11d0-bde2-00aa001a1953}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{03022430-abc4-11d0-bde2-00aa001a1953}\typelib:: {1EA4DBF0-3C3B-11CF-810C-00AA00389B71} RegNtPreCreateKey
HKLM\software\classes\interface\{03022430-abc4-11d0-bde2-00aa001a1953}\typelib::version 1.1 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 m� xy* �/��Y�d�� ��ރ�p ��^�o�<Vs}kP~��1!��7 ���ﺃee����1(��fe��h�n�iUe��rG RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ฿ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 n� xy* �/��Y�d�� ��ރ�p ��^�o�=Vs}kP~��1!��7 ���ﺃee����1(��fe��h�n�iUe��rG RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 홲༅ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 o� xy* �/��Y�d�� ��ރ�p ��^�o�>Vs}kP~��1!��7 ���ﺃee����1(��fe��h�n�iUe��rG RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 p� xy* �/��Y�d�� ��ރ�p ��^�o�?Vs}kP~��1!��7 ���ﺃee����1(��fe��h�n�iUe��rG RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 喻࿨ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 q� xy* �/��Y�d�� ��ރ�p ��^�o�@Vs}kP~��1!��7 ���ﺃee����1(��fe��h�n�iUe��rG RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ᗸ၊ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��  xy* �/��Y�d�kP~� ��ރ�p*��^�o�eebVs}EkP~E��1B��7 ���ﺃePe���"D��1X��fe��g� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 줝֔﯒ǜ RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Keyboard Access
  • GetKeyState
Network Wininet
  • InternetOpen
  • InternetOpenUrl
  • InternetReadFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
  • ShellExecuteEx
  • WriteConsole
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Terminate
  • TerminateProcess

Shell Command Execution

C:\WINDOWS\system32\wbuxx.exe "C:\WINDOWS\system32\wbuxx.exe"
Open C:\WINDOWS\system32\wbuxx
C:\WINDOWS\system32\cmd.exe "C:\WINDOWS\system32\cmd.exe" /c del "c:\users\user\downloads\0dd2621e4808d6af686656e0b97b6ef929c42222_0000089739"
Open C:\WINDOWS\system32\cmd.exe /c del "c:\users\user\downloads\0dd2621e4808d6af686656e0b97b6ef929c42222_0000089739"
C:\WINDOWS\system32\wjyk.exe "C:\WINDOWS\system32\wjyk.exe"
Show More
Open C:\WINDOWS\system32\wjyk
C:\WINDOWS\system32\cmd.exe "C:\WINDOWS\system32\cmd.exe" /c del "c:\users\user\downloads\193d02b0f5357de5c08df60210ac471d44570b0a_0000089101"
Open C:\WINDOWS\system32\cmd.exe /c del "c:\users\user\downloads\193d02b0f5357de5c08df60210ac471d44570b0a_0000089101"
C:\WINDOWS\system32\wwddnu.exe "C:\WINDOWS\system32\wwddnu.exe"
Open C:\WINDOWS\system32\wwddnu
Open C:\WINDOWS\system32\cmd.exe /c del "C:\WINDOWS\system32\wjyk.exe"
C:\WINDOWS\system32\wgppfa.exe "C:\WINDOWS\system32\wgppfa.exe"
Open C:\WINDOWS\system32\wgppfa
C:\WINDOWS\system32\cmd.exe "C:\WINDOWS\system32\cmd.exe" /c del "C:\WINDOWS\system32\wwddnu.exe"
Open C:\WINDOWS\system32\cmd.exe /c del "C:\WINDOWS\system32\wwddnu.exe"
WriteConsole: Could Not Find C
C:\WINDOWS\system32\wrmhvxr.exe "C:\WINDOWS\system32\wrmhvxr.exe"
Open C:\WINDOWS\system32\wrmhvxr
Open C:\WINDOWS\system32\cmd.exe /c del "C:\WINDOWS\system32\wgppfa.exe"
C:\WINDOWS\system32\wfyoduu.exe "C:\WINDOWS\system32\wfyoduu.exe"
Open C:\WINDOWS\system32\wfyoduu
C:\WINDOWS\system32\cmd.exe "C:\WINDOWS\system32\cmd.exe" /c del "C:\WINDOWS\system32\wrmhvxr.exe"
Open C:\WINDOWS\system32\cmd.exe /c del "C:\WINDOWS\system32\wrmhvxr.exe"
C:\WINDOWS\system32\wnwk.exe "C:\WINDOWS\system32\wnwk.exe"
Open C:\WINDOWS\system32\wnwk
C:\WINDOWS\system32\cmd.exe "C:\WINDOWS\system32\cmd.exe" /c del "C:\WINDOWS\system32\wfyoduu.exe"
Open C:\WINDOWS\system32\cmd.exe /c del "C:\WINDOWS\system32\wfyoduu.exe"
C:\WINDOWS\system32\wbcal.exe "C:\WINDOWS\system32\wbcal.exe"
Open C:\WINDOWS\system32\wbcal
C:\WINDOWS\system32\cmd.exe "C:\WINDOWS\system32\cmd.exe" /c del "c:\users\user\downloads\a8e792543157c0064bc50395b55ad8ea742c882f_0000089257"
Open C:\WINDOWS\system32\cmd.exe /c del "c:\users\user\downloads\a8e792543157c0064bc50395b55ad8ea742c882f_0000089257"

Trending

Most Viewed

Loading...