Home Malware Programs Trojans Trojan.Dropper.Agent

Trojan.Dropper.Agent

Posted: October 23, 2008

Threat Metric

Ranking: 7,899
Threat Level: 8/10
Infected PCs: 455,777
First Seen: July 24, 2009
Last Seen: February 20, 2025
OS(es) Affected: Windows

Trojan.Dropper.Agent is a serious Trojan downloader infection. Trojan.Dropper.Agent is known to download or even install other malicious files and programs onto an infected computer. Trojan.Dropper.Agent does this without letting the computer user know what is happening. You may notice slower computer performance and decreased network speed if you have the Trojan.Dropper.Agent Trojan horse infection. Trojan.Dropper.Agent is a serious threat to the security, personal and financial data stored on your computer. It is recommended that you detect and remove Trojan.Dropper.Agent with a good spyware scan tool.

Aliases

Agent.AXKV [AVG]W32/Agent.AGLX!tr [Fortinet]Trojan-PWS.Win32.Nilage.bbr [Ikarus]Dropper/Win32.OnlineGameHack [AhnLab-V3]PWS:Win32/QQpass.BC [Microsoft]Mal/HckPk-C [Sophos]TR/Dldr.Agent.beiq [AntiVir]TrojWare.Win32.TrojanDropper.Agent.aglx [Comodo]Trojan.Downloader.JLEA [BitDefender]Trojan-Dropper.Win32.Agent.aglx [Kaspersky]W32/Heuristic-210!Eldorado [F-Prot]Generic PWS.y [McAfee]TrojanDropper.Agent.aglx [CAT-QuickHeal]Injector.DXB [AVG]W32/Refroso.IGN!tr [Fortinet]
More aliases (362)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\wta40029.exe File name: wta40029.exe
Size: 345.28 KB (345288 bytes)
MD5: a3eccb5fe657617380f3384ad00fcb58
Detection count: 281
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 11, 2017
C:\Users\<username>\AppData\Local\Temp\g.exe File name: g.exe
Size: 4.6 MB (4602880 bytes)
MD5: 6addfd7a4ffe8a0760eaf75c7e6e093c
Detection count: 89
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\g.exe
Group: Malware file
Last Updated: December 16, 2022
C:\Users\<username>\AppData\Roaming\9gzi4\vsahy.exe File name: vsahy.exe
Size: 246.78 KB (246784 bytes)
MD5: 3aca09ff120d9422b665192878328da9
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\9gzi4
Group: Malware file
Last Updated: September 7, 2018
%WINDIR%\rss\csrss.exe File name: csrss.exe
Size: 4.91 MB (4913152 bytes)
MD5: fa348b6cf007a950740eb95ae0d8fb3b
Detection count: 65
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\rss
Group: Malware file
Last Updated: September 13, 2017
%ALLUSERSPROFILE%\wta8868.exe File name: wta8868.exe
Size: 394.44 KB (394440 bytes)
MD5: cf37b2aab3e1e0a5055bdd85a50f0243
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 11, 2017
%ALLUSERSPROFILE%\wta39960.exe File name: wta39960.exe
Size: 406.72 KB (406728 bytes)
MD5: 49947356cd5f7682da2d9ed0d4f97e0f
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 11, 2017
name.exe File name: name.exe
Size: 6.32 MB (6323200 bytes)
MD5: 217abb37d27df329ccf81282edf9211e
Detection count: 32
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ALLUSERSPROFILE%\wta1249.exe File name: wta1249.exe
Size: 406.72 KB (406728 bytes)
MD5: 1bc123854491ad8e71c6576c9332580a
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 11, 2017
%ALLUSERSPROFILE%\wta62744.exe File name: wta62744.exe
Size: 349.38 KB (349384 bytes)
MD5: c6448dfdced6853762a0e0c1279e0f36
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 11, 2017
%ALLUSERSPROFILE%\wta36041.exe File name: wta36041.exe
Size: 394.44 KB (394440 bytes)
MD5: 6975ee1a03995a90ef2cac3d46a8e55e
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 11, 2017
C:\Users\<username>\AppData\Local\Temp\APD4qVhLr\APD4qVhLr.exe File name: APD4qVhLr.exe
Size: 4.83 MB (4837888 bytes)
MD5: 4ecb8775e5a616d5c221dbf5d333c146
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\APD4qVhLr\APD4qVhLr.exe
Group: Malware file
Last Updated: August 22, 2021
%ALLUSERSPROFILE%\wta47758.exe File name: wta47758.exe
Size: 394.44 KB (394440 bytes)
MD5: bce5b054078a4686614f0ff843102b22
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 11, 2017
%ALLUSERSPROFILE%\wta10760.exe File name: wta10760.exe
Size: 485 KB (485007 bytes)
MD5: 76d8a5de6582f2474fa1ee836184c9a0
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 11, 2017
%ALLUSERSPROFILE%\wta51512.exe File name: wta51512.exe
Size: 349.38 KB (349384 bytes)
MD5: 600c4cd9a6f50bc985eacf74d9a99e7f
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 11, 2017
%ALLUSERSPROFILE%\wta16625.exe File name: wta16625.exe
Size: 320.69 KB (320696 bytes)
MD5: 644cfc1e631766d9060d7e1150f062d4
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 11, 2017
%ALLUSERSPROFILE%\wta36134.exe File name: wta36134.exe
Size: 406.72 KB (406728 bytes)
MD5: b2db2b0b96b6e9a5f0ed2e4b6cf6f0d0
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 11, 2017
%ALLUSERSPROFILE%\wta58939.exe File name: wta58939.exe
Size: 349.38 KB (349384 bytes)
MD5: 0f78353b355e5fb0c068c1565a25934f
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 11, 2017
%ALLUSERSPROFILE%\wta11330.exe File name: wta11330.exe
Size: 349.38 KB (349384 bytes)
MD5: 8c121308b7bd7d1265b6384e3d3a27b7
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 11, 2017
%ALLUSERSPROFILE%\wta28280.exe File name: wta28280.exe
Size: 349.38 KB (349384 bytes)
MD5: 6824d3d66373de6d40d68a676412436e
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 11, 2017
%ALLUSERSPROFILE%\wta38380.exe File name: wta38380.exe
Size: 349.38 KB (349384 bytes)
MD5: fe5ccb38ef06f5e5aa2a2824aed64984
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 11, 2017
%ALLUSERSPROFILE%\wta44399.exe File name: wta44399.exe
Size: 406.72 KB (406728 bytes)
MD5: 30d77ac27badafaf7c9eec0d5e75d064
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 11, 2017
%ALLUSERSPROFILE%\wta19530.exe File name: wta19530.exe
Size: 337.08 KB (337080 bytes)
MD5: 6e199631d2bfdc94119e3c603d05763b
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 11, 2017
%ALLUSERSPROFILE%\wta4415.exe File name: wta4415.exe
Size: 320.69 KB (320696 bytes)
MD5: 293ec9807f740d079fd9b46514af1a90
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 11, 2017

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%ALLUSERSPROFILE%\Application Data\Windows Shell Experiment.exe%ALLUSERSPROFILE%\Application Data\wta[NUMBERS].exe%ALLUSERSPROFILE%\Microsoft Services\lsm.exe%ALLUSERSPROFILE%\Windows Shell Experiment.exe%ALLUSERSPROFILE%\wta[NUMBERS].exe%APPDATA%\AdobeUpdate\AdobeUpdate.exe%APPDATA%\Maintenance\apps\maintenance.exe%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\The.Family.exe%APPDATA%\WindowsDefender\MSASCuiL.exe%TEMP%\The.Family.exe%WINDIR%\Install_WM.exe%WINDIR%\RSS\csrss.exe%WINDIR%\System32\Tasks\nethost task%WINDIR%\Tasks\nethost task.job

Additional Information

The following directories were created:
%APPDATA%\Java Sun

Related Posts

Loading...