Home Malware Programs Trojans Trojan Horse Agent3.AYIB

Trojan Horse Agent3.AYIB

Posted: December 7, 2011

Threat Metric

Ranking: 2,802
Threat Level: 8/10
Infected PCs: 91,635
First Seen: December 7, 2011
Last Seen: October 17, 2023
OS(es) Affected: Windows

Trojan Horse Agent3.AYIB is a malicious Trojan that emerges only when active. Trojan Horse Agent3.AYIB creates copies of itself. Trojan Horse Agent3.AYIB displays fake security warnings. Trojan Horse Agent3.AYIB may slow your computer and steal personal information. Trojan Horse Agent3.AYIB may open security back doors and download and install additional malware threats. Trojan Horse Agent3.AYIB may be hard to uninstall manually. Remove Trojan Horse Agent3.AYIB immediately after detection.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\Desktop\bb18d23bf4be9333adacb8661d03908c3e465c5a3b778170b18cc53077bccb95.exe File name: bb18d23bf4be9333adacb8661d03908c3e465c5a3b778170b18cc53077bccb95.exe
Size: 415.74 KB (415744 bytes)
MD5: 76cc8d23dc9c01388e0ae17a067ef80c
Detection count: 74
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\Desktop\bb18d23bf4be9333adacb8661d03908c3e465c5a3b778170b18cc53077bccb95.exe
Group: Malware file
Last Updated: February 27, 2021
C:Windowsfake explorer.exe File name: C:Windowsfake explorer.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:Program Files[RANDOM CHARACTERS].exe File name: C:Program Files[RANDOM CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:Documents and SettingsUser nameLocalSettingsTemporary Internet FilesContent[RANDOM CHARACTERS] File name: C:Documents and SettingsUser nameLocalSettingsTemporary Internet FilesContent[RANDOM CHARACTERS]
Group: Malware file
C:WindowsSystem32fake dwm.exe File name: C:WindowsSystem32fake dwm.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:WindowsSystem32fake taskhost.exe File name: C:WindowsSystem32fake taskhost.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:WindowsSystem32fake wuauclt.exe File name: C:WindowsSystem32fake wuauclt.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun[RANDOM CHARACTERS].exeHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServices[RANDOM CHARACTERS]HKEY_LOCAL_MACHINESYSTEMControlSet001EnumRootLEGACY_MYNAME000Control
Loading...