Home Malware Programs Trojans Trojan-dropper.win32.VB.agtq

Trojan-dropper.win32.VB.agtq

Posted: August 22, 2011

Trojan-dropper.win32.VB.agtq is a Visual Basic Trojan that is focused on installing other forms of harmful software onto your PC, potentially including Remote Administration Tools, keyloggers, ransomware Trojans or rogue security programs. In spite of this, SpywareRemove.com malware experts have also noted that Trojan-dropper.win32.VB.agtq may perform other attacks along the way to its primary goals, and is very likely to result in browser hijacks, altered system settings and disabled security features. Trojan-dropper.win32.VB.agtq should be considered a high-priority threat to your PC whenever you suspect that you've been infected, and Trojan-dropper.win32.VB.agtq removal can be best done by a dedicated anti-malware product that's been updated for recent threat definitions.

Anticipating Trojan-dropper.win32.VB.agtq's Swipes at Your PC

Although many of its characteristics can vary depending on which variant your PC has been attacked by, Trojan-dropper.win32.VB.agtq primarily places your computer at risk for attacks like the following:

  • Trojan-dropper.win32.VB.agtq may install other harmful applications onto your PC. These programs can include scamware (such as File Repair or Windows System Manager), spyware (such as Trojan.GameThief.WOW.bht or Zeus Keylogger), other Trojans (such as Trojan Downloader.mb or Backdoor.Win32.Bredolab.obk) and many other types of infections.
  • To enable its downloading attacks or in additions to such attacks, Trojan-dropper.win32.VB.agtq may also reduce your computer's security, primarily by altering system settings via the Windows Registry. These changes can include disabling System Restore or Safe Mode, altering your file-viewing preferences, opening networks ports and adding exceptions to your firewall.
  • Trojan-dropper.win32.VB.agtq may be instructed to act in the form of a RAT or Remote Administration Tool. SpywareRemove.com malware analysts have noted that the threat that's posed by such infections is extremely serious, since they may allow remote hackers to take complete control over the system for a variety of illegal activities, most prominently including identity theft and DDoS attacks.

How Trojan-dropper.win32.VB.agtq Gets Away with It All

Most variants of Trojan-dropper.win32.VB.agtq will use Registry-based startup entries to trigger themselves whenever Windows launches. However, on one can guarantee that you will be capable of detecting Trojan-dropper.win32.VB.agtq's files or memory processes, since these components may be named randomly or named after normal system components like lsass.exe.

Additionally, Trojan-dropper.win32.VB.agtq may show no serious symptoms of being active and attacking your PC, besides the unavoidable side effects of its malicious actions, such as browser hijacks, system slowdown and the presence of unusual programs on your hard drive. Because Trojan-dropper.win32.VB.agtq's symptoms are minimal and may vary widely due to variations in code and remote instructions from hackers, you shouldn't try to detect Trojan-dropper.win32.VB.agtq without assistance.

In all cases, the readiest-available solution to any Trojan-dropper.win32.VB.agtq infection is to launch a complete scan of your PC with an anti-malware product, preferably one that has been updated for all threat definitions. SpywareRemove.com malware researchers also note that using Safe Mode for this scan will increase your chances of deleting Trojan-dropper.win32.VB.agtq without any problems.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ASFFile\shell\pipiopenHKEY_LOCAL_MACHINE\SOFTWARE\Classes\ASFFile\shell\pipiopen\command (Default) = "Play With PIPIPlayer"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AVIFile\shell\pipiopen (Default) = ""%ProgramFiles%\pipi\PIPIPlayer.exe" "%L""HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AVIFile\shell\pipiopen\command
Loading...