Home Malware Programs Trojans Trojan-Dropper.Win32.Agent.xzr

Trojan-Dropper.Win32.Agent.xzr

Posted: April 18, 2011

Trojan-Dropper.Win32.Agent.xzr is a malicious backdoor trojan that runs in the background and enables a hacker remote access to the targeted computer system. Trojan-Dropper.Win32.Agent.xzr initiates automatically when computer boots up because it has dropped its start-up item in the registry entry. Trojan-Dropper.Win32.Agent.xzr will download files to the computer without a victim's consent which will lead to security threat. Trojan-Dropper.Win32.Agent.xzr can propagate via network if the malicious drive is shared at the network.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Bifrost\server.exe
    2 %System%\molebox.exe
    3 %System%\server1.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\032HKEY_LOCAL_MACHINE\SOFTWARE\032HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideoHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
Loading...