Home Malware Programs Trojans TrojanDownloader:AutoIt/Agent.J

TrojanDownloader:AutoIt/Agent.J

Posted: December 11, 2012

Threat Metric

Ranking: 1,775
Threat Level: 8/10
Infected PCs: 210,677
First Seen: December 11, 2012
Last Seen: March 8, 2025
OS(es) Affected: Windows

Aliases

Trj/CI.A [Panda]Generic6_c.BUMR [AVG]W32/Grp.GA!tr [Fortinet]Win32.AutoIt [Ikarus]Backdoor/Win32.ZAccess [AhnLab-V3]TrojanDownloader:AutoIt/Agent.J [Microsoft]TR/Agent.281211 [AntiVir]Trojan.DownLoader5.42373 [DrWeb]UnclassifiedMalware [Comodo]Mal/Generic-L [Sophos]Backdoor.Win32.ZAccess.zii [Kaspersky]Win32:AutoIt-ALZ [Trj] [Avast]WS.Reputation.1 [Symantec]Riskware [K7AntiVirus]Generic.grp!ga [McAfee]
More aliases (27)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Roaming\ythgrfed.exe File name: ythgrfed.exe
Size: 19.12 MB (19128320 bytes)
MD5: 3ba321ee9799577ab20f40743f90421a
Detection count: 604
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: August 22, 2021
%SYSTEMDRIVE%\Users\<username>\appdata\roaming\microsoft\windows\helper.exe File name: helper.exe
Size: 7.58 MB (7586816 bytes)
MD5: 66a55f9baf27d573e0b4116b4d552380
Detection count: 98
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\appdata\roaming\microsoft\windows
Group: Malware file
Last Updated: April 2, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\x86_microsoft-windows-ie-imagesupport\dpnlobby.exe File name: dpnlobby.exe
Size: 2.62 MB (2622976 bytes)
MD5: 8d0a7ac3647224c6c882e164a578c17d
Detection count: 68
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\x86_microsoft-windows-ie-imagesupport\dpnlobby.exe
Group: Malware file
Last Updated: August 5, 2020
C:\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SoftwareUpdaterService.exe File name: SoftwareUpdaterService.exe
Size: 704.43 KB (704437 bytes)
MD5: ce4c37b485f6c2a463e70348fbb5575f
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: May 12, 2020
C:\Users\<username>\AppData\Roaming\User\app.exe File name: app.exe
Size: 669.69 KB (669696 bytes)
MD5: bf2aa49a532f3a01ff926884bdcbb1eb
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\User\app.exe
Group: Malware file
Last Updated: December 27, 2024
%SYSTEMDRIVE%\Users\<username>\Desktop\5557028791025664\afd519f0a8b99b9c3ea46000ec8699b11284eef09727ee668a4efde8ba25ffca File name: afd519f0a8b99b9c3ea46000ec8699b11284eef09727ee668a4efde8ba25ffca
Size: 742.4 KB (742400 bytes)
MD5: 54b97b5e2b29aee504559abc6aa0ed70
Detection count: 30
Path: %SYSTEMDRIVE%\Users\<username>\Desktop\5557028791025664\afd519f0a8b99b9c3ea46000ec8699b11284eef09727ee668a4efde8ba25ffca
Group: Malware file
Last Updated: August 19, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Apple Computer\MobileSync\Backup\b52f312198de5c4dde213670227f41b5e16a42db-20181122-032541\90\90b0abb7b61c8ee659bc4d1c863f9e2b42213632 File name: 90b0abb7b61c8ee659bc4d1c863f9e2b42213632
Size: 966.75 KB (966757 bytes)
MD5: bc7eec8a90f799f80dda8177f2abb3a2
Detection count: 23
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Apple Computer\MobileSync\Backup\b52f312198de5c4dde213670227f41b5e16a42db-20181122-032541\90\90b0abb7b61c8ee659bc4d1c863f9e2b42213632
Group: Malware file
Last Updated: May 4, 2021
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\initsrv.exe File name: initsrv.exe
Size: 483.42 KB (483425 bytes)
MD5: d249778acb9923f3bf6adf075a8778de
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\initsrv.exe
Group: Malware file
Last Updated: June 27, 2020
C:\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\system.pifx File name: system.pifx
Size: 774.14 KB (774144 bytes)
MD5: c68c74df81edfea4c3ceb9861b5d69e9
Detection count: 19
Mime Type: unknown/pifx
Path: C:\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: October 22, 2021
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\amd64_mdmgl008.inf\wdc.exe File name: wdc.exe
Size: 3.63 MB (3636736 bytes)
MD5: ea465f0ce93c67dd6e083fbd79d03d17
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\amd64_mdmgl008.inf\wdc.exe
Group: Malware file
Last Updated: July 1, 2021
c:\windows\shtsenv.exe File name: shtsenv.exe
Size: 1.04 MB (1044992 bytes)
MD5: f8438b55ff1d37ea940bfdf19dad99da
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: c:\windows
Group: Malware file
Last Updated: February 8, 2020
C:\Users\<username>\AppData\Roaming\minecrak\assets\assets .exe File name: assets .exe
Size: 617.47 KB (617472 bytes)
MD5: 1e4feeeb8674a01df333c9cb6f858ae8
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\minecrak\assets\assets .exe
Group: Malware file
Last Updated: January 29, 2021
C:\Users\<username>\AppData\Roaming\MajorAV\Quarantine\2020-08-190805\qxgMPdgN8RB2.exe#338d2c2a File name: qxgMPdgN8RB2.exe#338d2c2a
Size: 985.6 KB (985600 bytes)
MD5: 7bb1ba7cfadbc02522b1113f488f9e3a
Detection count: 12
Mime Type: unknown/exe#338d2c2a
Path: C:\Users\<username>\AppData\Roaming\MajorAV\Quarantine\2020-08-190805\qxgMPdgN8RB2.exe#338d2c2a
Group: Malware file
Last Updated: April 10, 2021
C:\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Activation.exe File name: Activation.exe
Size: 1.09 MB (1098752 bytes)
MD5: fdf2edc611c6a1b0d14290cb75326763
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: January 31, 2020
c:\Users\<username>\appdata\local\temp\rar$exa0.790\steam key generator\steam key generator.exe File name: steam key generator.exe
Size: 12.11 MB (12117504 bytes)
MD5: 3313ab2e6adab202c44a2354374a43aa
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: c:\Users\<username>\appdata\local\temp\rar$exa0.790\steam key generator
Group: Malware file
Last Updated: September 10, 2020
%SYSTEMDRIVE%\Users\<username>\appdata\roaming\adobeart.exe File name: adobeart.exe
Size: 1.9 MB (1907028 bytes)
MD5: bdf282bbd43e8de3654a440255da1632
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\appdata\roaming
Group: Malware file
Last Updated: September 28, 2020
C:\Windows\SysWOW64\realtek\csrss.exe File name: csrss.exe
Size: 938.77 KB (938775 bytes)
MD5: 385c0e62425caba1cda72dbac1e8b318
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\SysWOW64\realtek
Group: Malware file
Last Updated: August 19, 2020
c:\windows\temp\_avg_\unp2451684.tmp File name: unp2451684.tmp
Size: 2.14 MB (2149376 bytes)
MD5: 0af565985c8d1e27b520af2122489a75
Detection count: 5
File type: Temporary File
Mime Type: unknown/tmp
Path: c:\windows\temp\_avg_
Group: Malware file
Last Updated: September 2, 2020

More files

Registry Modifications

The following newly produced Registry Values are:

File name without path! My Image.scrtmpe0d.tmp.google.exeRegexp file mask%APPDATA%\cmitros.exe%APPDATA%\install\win32.exe%APPDATA%\keep.exe%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\20109297886[NUMBERS].exe%appdata%\microsoft\windows\start menu\programs\startup\autoupdatedl.exe%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\cmitros.exe%APPDATA%\regsvr.exe%HOMEDRIVE%\Google\EXLE.exe%HOMEDRIVE%\googlechrome\googlechrome.a3x%HOMEDRIVE%\googlechrome\googlechrome.exe%HOMEDRIVE%\googlechrome\googlechrome.lnk%HOMEDRIVE%\googlechrome\GoogleUpdate.lnk%HOMEDRIVE%\googlechrome\WindowsUpdate.lnk%HOMEDRIVE%\mozillafirefox\googlechrome.exe%LOCALAPPDATA%\start\update.exe%temp%\file.exe%WINDIR%\svhost.exe%WINDIR%\system32\install\win32.exe%WINDIR%\SysWOW64\install\win32.exe

Additional Information

The following directories were created:
%APPDATA%\Windata%APPDATA%\lazagne%USERPROFILE%\LegacyNetUXHost%WINDIR%\cidd_p
Loading...