Home Malware Programs Trojans Trojan-Downloader.VBS.Agent

Trojan-Downloader.VBS.Agent

Posted: November 17, 2009

Trojan-Downloader.VBS.Agent is a devious Trojan horse that secretly enters a computer or network and opens up backdoors to welcome a multitude of malware to the infected system. Trojan-Downloader.VBS.Agent then modifies the system settings and creates a false start up registry. Trojan-Downloader.VBS.Agent also downloads of other spyware including a spyware keylogger which records keystrokes and captures the user's personal activity. Trojan-Downloader.VBS.Agent should not be given the freedom to do its dirty work and must be removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Windir%\105.exe
    2 %Windir%\ads.exe
    3 %Windir%\FunshionInstall_C43423.exe
    4 %Windir%\qvodsetup3.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E8CFC029-8420-4EAE-ADEF-915BDC77E1DC}\LocalServer32][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E8CFC029-8420-4EAE-ADEF-915BDC77E1DC}\ProgID][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E8CFC029-8420-4EAE-ADEF-915BDC77E1DC}][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\[filename of the sample #3 without extension].MyNSHandler\Clsid][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\[filename of the sample #3 without extension].MyNSHandler]
Loading...