English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Trojan-Dropper.Win32.Agent.vw

Detected Sep 29 2005 04:21 GMT
Released Sep 29 2005 04:21 GMT
Published Dec 05 2005 10:12 GMT

Technical Details

This Trojan downloads other malicious programs to the victim machine without the user's knowledge or consent. The Trojan is a Windows PE EXE file an is 262717 bytes in size.

When launched, this Trojan creates and then executes the following files:

The Trojan then registers bpk.exe in the system registry, ensuring that it will be launched each time Windows is rebooted on the victim machine.

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"bpk" = "%System%\bpk.exe"

The Trojan also creates files with the following names on the victim machine:

%System%\bpk.dat
%System%\inst.dat
%System%\kw.dat
%System%\pk.bin

Bookmark and Share
Share
Trojan-Dropper

Trojan-Dropper programs are designed to secretly install malicious programs built into their code to victim computers.

This type of malicious program usually save a range of files to the victim’s drive (usually to the Windows directory, the Windows system directory, temporary directory etc.), and launches them without any notification (or with fake notification of an archive error, an outdated operating system version, etc.).

Such programs are used by hackers to:

  • secretly install Trojan programs and/or viruses
  • protect known malicious programs from being detected by antivirus solutions; not all antivirus programs are capable of scanning all the components inside this type of Trojans.

Other versions