Home→Descriptions→Trojan.MSIL.Agent.azy
| Detected | Feb 10 2011 04:43 GMT |
| Released | Feb 10 2011 11:20 GMT |
| Published | Mar 16 2011 12:20 GMT |
This malicious program provides a malicious user with remote access to the infected computer. It is a Windows .NET application (PE EXE file) and is 39 424 bytes in size.
Once launched, the backdoor establishes a connection with this server:
in***aca.comA combination of the following strings is used as a login and password:
zxm1987 1 123 1234 12345 123456 12345678 adminOther malicious programs may be downloaded from the above-mentioned server to the user's computer. In addition, following a command received from the malicious user's server, the backdoor may perform the following actions:
[HKLM\Software\Microsoft\Jet\4.0\Engines] "SandBoxMode"' [HKLM\Software\Microsoft\Windows NT\CurrentVersion\ Image File Execution Options] [HKLM\Software\Microsoft\Command Processor] "AutoRun"
If your computer does not have an antivirus, and is infected by this malicious program, follow the instructions below to delete it:
MD5: ED92A9F7D48D3FBDA17F8ADCFE282D34
SHA1: BC5C19E8F58DE97B18B3DB482D9661B464C78B8B
This type of behaviour covers malicious programs that delete, block, modify, or copy data, disrupt computer or network performance, but which cannot be classified under any of the behaviours identified above.
This classification also covers “multipurpose” Trojan programs, i.e. those that are capable of conducting several actions at once and which demonstrate several Trojan behaviours in a single program. This means they cannot be indisputably classified as having any single behaviour.