Home Malware Programs Trojans Trojan-PSW.Win32.Agent.oht

Trojan-PSW.Win32.Agent.oht

Posted: May 12, 2011

Trojan-PSW.Win32.Agent.oht is a nasty trojan infection which uses malicious tricks to download harmful malware from the Internet. Trojan-PSW.Win32.Agent.oht penetrates and installs the affected computer without a victim's awareness or authorization when you open an unidentified email attachment, image, use instant messaging, etc. Trojan-PSW.Win32.Agent.oht mainly operates by downloading files to the targeted computer system without user's knowledge. Trojan-PSW.Win32.Agent.oht is a security threat to computer system and has to be removed from the PC immediately once it has been detected.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\Xenocode\Sandbox\pluginplus\1.00\2010.10.18T18.57\Native\STUBEXE\@SYSTEM@\drwtsn32.exe
    2 %AppData%\Xenocode\Sandbox\pluginplus\1.00\2010.10.18T18.57\Native\STUBEXE\@WINDIR@\101.exe
    3 %AppData%\Xenocode\Sandbox\pluginplus\1.00\2010.10.18T18.57\Virtual\STUBEXE\@SYSTEM@\Select Password.exe
    4 %System%\101.txt
    5 %System%\102.txt
    6 %System%\103.txt
    7 %System%\104.txt
    8 %System%\105.txt
    9 %System%\107.txt
    10 %System%\108.txt
    11 %System%\IPStore.idl
    12 %System%\IPStore.tlb
    13 %System%\OEAcc.odl
    14 %System%\OEAcc.tlb
    15 %Windir%\101.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\XenocodeHKEY_CURRENT_USER\Software\Xenocode\SandboxCacheHKEY_CURRENT_USER\Software\Xenocode\SandboxCache\9001739CHKEY_CURRENT_USER\Software\Xenocode\SandboxCache\9001739C\VirtualHKEY_CURRENT_USER\Software\Xenocode\SandboxCache\9001739C\Virtual\MODIFIEDHKEY_CURRENT_USER\Software\Xenocode\SandboxCache\9001739C\Virtual\MODIFIED\@HKCR@HKEY_CURRENT_USER\Software\Xenocode\SandboxCache\9001739C\Virtual\MODIFIED\@HKCR@\CLSIDHKEY_CURRENT_USER\Software\Xenocode\SandboxCache\9001739C\Virtual\MODIFIED\@HKLM@Read more how to delete Trojan-PSW.Win32.Agent.oht registry entries
Loading...