Home Malware Programs Trojans Trojan-Downloader.Agent!sd5

Trojan-Downloader.Agent!sd5

Posted: August 23, 2011

Trojan-Downloader.Agent!sd5 is identified as a Trojan infection that takes advantage of system vulnerabilities to spread and avoid detection from anti-virus software. Trojan-Downloader.Agent!sd5 can change your system files, harm computer system and gather personal information. Trojan-Downloader.Agent!sd5 allows remote attackers to access your compromised PC. Trojan-Downloader.Agent!sd5 needs to be removed as soon as possible with a dependable anti-malware program.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%AppData%\Microsoft\FineTop\FineTopUDF.exe File name: %AppData%\Microsoft\FineTop\FineTopUDF.exe
File type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\FineTop\1 File name: %ProgramFiles%\FineTop\1
%Temp%\FineTop_FT75.exe File name: %Temp%\FineTop_FT75.exe
File type: Executable File
Mime Type: unknown/exe
c:\DelUS.bat File name: c:\DelUS.bat
File type: Batch file
Mime Type: unknown/bat
%ProgramFiles%\FineTop\FineTop.exe File name: %ProgramFiles%\FineTop\FineTop.exe
File type: Executable File
Mime Type: unknown/exe

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{CLSID Path}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CBF53489-AD8D-4637-965A-413861EEC7CF}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FineTop.TopBand.1\CLSIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\FineTop.TopBand\CLSIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3E54C6DC-A2C6-404C-A36F-DE346281B3A7}\1.0\HELPDIRHKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3E54C6DC-A2C6-404C-A36F-DE346281B3A7}\1.0\FLAGSHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F1AACA8D-4899-4D6C-B360-403A5A20B5D2}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CBF53489-AD8D-4637-965A-413861EEC7CF}\VersionIndependentProgIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CBF53489-AD8D-4637-965A-413861EEC7CF}\TypeLibHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CBF53489-AD8D-4637-965A-413861EEC7CF}\ProgrammableHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CBF53489-AD8D-4637-965A-413861EEC7CF}\ProgIDHKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CBF53489-AD8D-4637-965A-413861EEC7CF}\InprocServer32HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CBF53489-AD8D-4637-965A-413861EEC7CF}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3E54C6DC-A2C6-404C-A36F-DE346281B3A7}\1.0\0\win32HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3E54C6DC-A2C6-404C-A36F-DE346281B3A7}\1.0\0HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3E54C6DC-A2C6-404C-A36F-DE346281B3A7}\1.0HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3E54C6DC-A2C6-404C-A36F-DE346281B3A7}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F1AACA8D-4899-4D6C-B360-403A5A20B5D2}\TypeLibHKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F1AACA8D-4899-4D6C-B360-403A5A20B5D2}\ProxyStubClsid32HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F1AACA8D-4899-4D6C-B360-403A5A20B5D2}\ProxyStubClsidHKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FineTop.TopBand.1HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FineTop.TopBand\CurVerHKEY_LOCAL_MACHINE\SOFTWARE\Classes\FineTop.TopBand
Loading...