Home Malware Programs Trojans Troj/Agent-WHZ

Troj/Agent-WHZ

Posted: May 22, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 76
First Seen: May 22, 2012
Last Seen: April 9, 2020
OS(es) Affected: Windows

Troj/Agent-WHZ is a Trojan that is included in a spam Facebook campaign related to account cancellation. The fake email that distributes Troj/Agent-WHZ asks the affected PC user to confirm account cancellation by clicking on the given link. However, the link doesn't take a PC user to an official Facebook web page, but a third-party application running on the Facebook platform, which means that the link goes to a facebook.com address, and thus, can confuse unwary online users. If a PC user clicks on the link, a message asking if he/she wants to allow an unknown Java application to run on the PC, will be shown. If a computer user hits the 'No thanks' button, a disturbing message will be continuously displayed on the screen. If a victim enables the program to run, he/she will see a message telling that Adobe Flash must be updated. The downloaded code detected as Troj/Agent-WHZ is, of course, not Adobe Flash update at all. In place of it, the software program adds extra malicious files into a /WIN32 folder, which have the purpose of permitting remote cybercriminals to spy on the affected computer user's online actions and obtain access and control over the infected machine.

Loading...