Home→Descriptions→Trojan.Win32.Agent2.lmu
| Detected | Jul 26 2010 05:39 GMT |
| Released | Jul 26 2010 12:48 GMT |
| Published | Sep 19 2011 15:21 GMT |
The trojan is a spyware component. It is a Windows dynamic-link library (PE-DLL file). 5120 bytes. UPX packed. Unpacked size – around 10 kB. Written in C++.
By loading any process to the address space, the malicious library installs a hook to track the messages in the system queue. The following "ws2_32.dll" library functions are also intercepted:
WSASend send recv WSARecvThis allows the trojan to track incoming and outgoing traffic for the infected process, recording the collected data to the following files:
%Temp%\mpz.tmp %Temp%\mpz.s %Temp%\r43q34.tmp c:\email_sent.txt c:\ftp.txt c:\email.txt
If your computer has not been protected with anti-virus software and has been infected with malware, you will need to take the following actions to delete this:
%Temp%\mpz.tmp %Temp%\mpz.s %Temp%\r43q34.tmp c:\email_sent.txt c:\ftp.txt c:\email.txt
MD5: D807AA04480D1D149F7A4CAC22984188
SHA1: FFD5BE65FD10017E34C11CECD105EBF4AA6C0CD9
This type of behaviour covers malicious programs that delete, block, modify, or copy data, disrupt computer or network performance, but which cannot be classified under any of the behaviours identified above.
This classification also covers “multipurpose” Trojan programs, i.e. those that are capable of conducting several actions at once and which demonstrate several Trojan behaviours in a single program. This means they cannot be indisputably classified as having any single behaviour.
Trojan.