Home→Descriptions→Trojan.Win32.Agent.fadd
| Detected | Aug 31 2010 11:39 GMT |
| Released | Aug 31 2010 19:29 GMT |
| Published | Mar 25 2011 08:13 GMT |
This Trojan delivers a malicious payload to the user's computer. It is a Windows application (PE EXE file). It is 49 162 bytes in size. It is written in Delphi.
Once launched, the Trojan moves its body into the file:
%APPDATA%\download2\svcnost.exeTo ensure that this file is launched automatically each time the system is rebooted, the following system registry key is created:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "download" = "%APPDATA%\download2\svcnost.exe"In addition, the file created is added to the list of applications trusted by Windows Firewall by creating the following system registry key:
[HKLM\System\CurrentControlSet\Services\SharedAccess\ Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%APPDATA%\download2\svcnost.exe" = "%APPDATA%\download2\svcnost.exe:*:Enabled:ldrsoft"
Once launched, the Trojan establishes a connection with the malicious user's server:
ca***dt.comand sends this server the following information about the system:
[HKCU\Software\Classes\http\shell\open\command]The following values may be sent:
IE Firefox Chrome Opera Mozila Safari Other
WinNT3 WinNT4 Win95 Win98 WinME Win2000 WinXP Win2003 Win7 Vista
avp. kav. nod32krn. ekrn.e mcshield. bdagent ofcdog srvload.e navapsvc.e ccsvchst.e spidernt.e dwengine.e winssui.e avastui.e avastsvc.ex avgrsx.e avgnt.e sched.eDepending on the processes found, the following values may be sent:
KIS Nod32 McAfee BitDefender TrendMicro Panda Norton OneCare Avast AVG Avira
%APPDATA%\download2Once downloaded, the files are launched for execution. At the time of writing, the server was inactive.
Also, as part of its operations, the Trojan creates the system registry key:
[HKCU\Software\Microsoft] "idln2" = "<rnd>"where <rnd> is a random sequence of characters (for example, "msdgynwcq1vrubzyvdx13iyvs3vgcke").
If your computer does not have an antivirus, and is infected by this malicious program, follow the instructions below to delete it:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "download" = "%APPDATA%\download2\svcnost.exe" [HKLM\System\CurrentControlSet\Services\SharedAccess\ Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%APPDATA%\download2\svcnost.exe" = "%APPDATA%\download2\svcnost.exe:*:Enabled:ldrsoft" [HKCU\Software\Microsoft] "idln2" = "<rnd>"
%APPDATA%\download2\svcnost.exe
%APPDATA%\download2
This type of behaviour covers malicious programs that delete, block, modify, or copy data, disrupt computer or network performance, but which cannot be classified under any of the behaviours identified above.
This classification also covers “multipurpose” Trojan programs, i.e. those that are capable of conducting several actions at once and which demonstrate several Trojan behaviours in a single program. This means they cannot be indisputably classified as having any single behaviour.
Trojan.