Home Malware Programs Trojans Trojan.Agent.ciel

Trojan.Agent.ciel

Posted: August 9, 2011

Trojan.Agent.ciel is a Trojan and, in many cases, a form of spyware that tries to steal password-related information. Nonetheless, SpywareRemove.com malware research team has found that even Trojan.Agent.ciel variants that lack any spyware functions remain very dangerous and have the potential to disable your computer's security or install innumerable other types of harmful applications. Since the signs of any individual Trojan.Agent.ciel infection may be negligible at first, you may need a powerful anti-malware program to detect Trojan.Agent.ciel in the first place, and deleting Trojan.Agent.ciel without such software is likewise improbable under most circumstances.

The Worst of Trojan.Agent.ciel's Spying Side

Some brands of anti-malware programs detect Trojan.Agent.ciel as an alias for spyware, including the dreaded Infostealer.Gampass, which is also known as PWS-WoW and PWS-Win32/Wowsteal.AO!dll. This version of Trojan.Agent.ciel attempts to steal passwords that are related to online game accounts, particularly accounts that are linked to the World of Warcraft mmorpg. However, standard spyware functions, such as keyloggers that record all keyboard input, are also capable of capturing other private data, such as social security numbers, credit card numbers and non-gaming passwords.

This variant of Trojan.Agent.ciel is especially difficult to detect, since almost all forms of spyware will do their best to conceal their activities and may even infect normal system processes to avoid detection. As a result, resorting to an anti-malware or anti-spyware product is the easiest way to uproot Trojan.Agent.ciel spyware.

Looking on the Flip-Side at Trojan.Agent.ciel's Trojan Attributes

Trojan.Agent.ciel Trojans may also exhibit other characteristics, depending on the variant and configuration instructions that may be used to alter Trojan.Agent.ciel's behavior. Some especially likely Trojan.Agent.ciel-related attacks include, but aren't restricted to:

  • Security setting-related attacks, such as altered network settings or weakened firewalls. If you see an unusual exception in your firewall or network ports that are open without your permission, Trojan.Agent.ciel may be the cause.
  • Program barricades that stonewall any attempts that you might make to access security programs to find or remove Trojan.Agent.ciel. In most cases, stopping Trojan.Agent.ciel from launching is the only thing that's necessary to allow you to regain the use of any blacklisted applications.
  • The installation of other types of harmful programs, including browser hijackers like Findxplorer or Resulturl, adware like Adware.Lop!rem and rogue security products such as Windows Startup Repair and WolfRam AntiVirus.

Variants of Trojan.Agent.ciel include Trojan.Agent.ciel.A and Trojan.Agent.ciel.B, which may show slightly modified but still harmful behavior. Because Trojan.Agent.ciel may use randomly-named files or files that are named to mimic natural system components (such as explorer.exe or firefox.exe), you should be careful to remove Trojan.Agent.ciel with an appropriate anti-malware programs instead of deleting Trojan.Agent.ciel without any assistance.

Trojan.Agent.ciel may also occur alongside other infections, including similar Trojans such as Trojan.Agent.aghn, Trojan.Agent.kvo, Trojan.Agent.Delf.GY, Trojan.Agent.amjj and Trojan.Agent.chjj.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



QoS.dll File name: QoS.dll
File type: Dynamic link library
Mime Type: unknown/dll
bbafgfbj.dll File name: bbafgfbj.dll
File type: Dynamic link library
Mime Type: unknown/dll
bpvol.dll File name: bpvol.dll
File type: Dynamic link library
Mime Type: unknown/dll
wicstd32.dll File name: wicstd32.dll
File type: Dynamic link library
Mime Type: unknown/dll
jfkrgotvbl.dll File name: jfkrgotvbl.dll
File type: Dynamic link library
Mime Type: unknown/dll

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINDOWS\APPINIT_DLLS\AppInit_DLLsHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\NOTIFY\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\windmh32HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNHKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\mbssm32HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\WMFMRNV
Loading...