Home→Descriptions→Trojan.Win32.Agent.fw
| Detected | Jul 18 2005 12:34 GMT |
| Released | Jul 18 2005 12:34 GMT |
| Published | Mar 15 2012 15:02 GMT |
When installed into the system, it connects to remote Command and Control center (C&C) every few minutes and receives additional instructions. It can be a command to download new malicious applications or various requests about stealing particular data from the infected computer.
CurrentUser\ApplicationData\Microsoft\SystemCertificates\My\CTL, CurrentUser\ApplicationData\Microsoft\SystemCertificates\My\CRL, CurrentUser\ApplicationData\Microsoft\SystemCertificates\My\Certificates.
CurrentUser\ApplicationData\Microsoft\SystemCertificates\My\CTL, CurrentUser\ApplicationData\Microsoft\SystemCertificates\My\CRL, CurrentUser\ApplicationData\Microsoft\SystemCertificates\My\Certificates
This type of behaviour covers malicious programs that delete, block, modify, or copy data, disrupt computer or network performance, but which cannot be classified under any of the behaviours identified above.
This classification also covers “multipurpose” Trojan programs, i.e. those that are capable of conducting several actions at once and which demonstrate several Trojan behaviours in a single program. This means they cannot be indisputably classified as having any single behaviour.
Trojan.