Home Malware Programs Trojans Trojan-Downloader.Win32.Agent.dnqk

Trojan-Downloader.Win32.Agent.dnqk

Posted: May 4, 2010

Trojan-Downloader.Win32.Agent.dnqk is a malicious Trojan that gains entry to a compromised computer or network via a backdoor. Trojan-Downloader.Win32.Agent.dnqk operates stealthily to download corrupt files to the local computer that may represent security risk. Do not give Trojan-Downloader.Win32.Agent.dnqk the leeway to cause chaos on your PC.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %CommonAppData%\Microsoft\Crypto\RSA\S-1-5-1\6d14e4b1d8ca773bab785d1be032546e_a7bcc1a4-f7a4-4502-8650-8579e607f7f7
    2 %System%\drivers\asyncmac.sys.bak
    3 %Temp%\6f6c94f6.tmp
    4 %Windir%\Temp\3880482436a29dbd650adab3.tmp
    5 %Windir%\Temp\7e74cf496d7b67dd54b687.tmp
    6 %Windir%\Temp\97ab51e49bfab87d3e264605.tmp
    7 %Windir%\Temp\bd078fd4fee1c608ba7cea38.tmp
    8 %Windir%\Temp\bf82f37060168350d1270aa6.tmp
    9 %Windir%\Temp\c7f4dbef5aedf050d1cc22aa.tmp

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]HKEY..\..\..\..{RegistryKeys}[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters][HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac\Device Parameters][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\SW\{eeab7790-c514-11d1-b42b-00805fc1270e}\asyncmac]
Loading...