Home→Descriptions→Trojan.Win32.Agent2.ddnd
| Detected | Mar 03 2011 23:25 GMT |
| Released | Mar 04 2011 06:17 GMT |
| Published | Sep 19 2011 12:57 GMT |
A trojan program that downloads files from the Internet without the user's knowledge and launches them. It is a Windows application (PE-EXE file). 8704 bytes. Written in C++.
The trojan creates a system registry key to automatically launch its original file when the system is next loaded up:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "<name of the executable trojan file without extension>" = "<full path to the original trojan file>"
After launching, the trojan carries out the following actions in an infinite loop:
http://www.aca****ctreks.com/postinfo.html
%Temp%\<FileName>.exeThe <FileName> is taken from the link.
Depending on the result of the download, the time between the loop iterations may be 8, 10, 90, or 100 minutes.
If your computer has not been protected with anti-virus software and has been infected with malware, you will need to take the following actions to delete this:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "<name of the executable trojan file without extension>" = "<full path to the original trojan file>"
MD5: FED763A86628E820EEE6C9C8547FECB1
SHA1: C60D2E07D025B7AB09FF4B10999838758BF24B7A
This type of behaviour covers malicious programs that delete, block, modify, or copy data, disrupt computer or network performance, but which cannot be classified under any of the behaviours identified above.
This classification also covers “multipurpose” Trojan programs, i.e. those that are capable of conducting several actions at once and which demonstrate several Trojan behaviours in a single program. This means they cannot be indisputably classified as having any single behaviour.