Home Malware Programs Trojans Trojan horse Agent_r.AOB

Trojan horse Agent_r.AOB

Posted: August 30, 2011

Trojan horse Agent_r.AOB is a malicious Trojan that enters the infected computer system via Facebook chats or instant messages without a user's consent and knowledge. Trojan horse Agent_r.AOB uses compromised PCs to deliver additional malware threats, send spam messages and create 'pay per click' advertising revenue. Trojan horse Agent_r.AOB makes modifications to registry entries to damage computer systems. Delete Trojan horse Agent_r.AOB as quickly as possible to secure your computer system.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



c:\facebook Browse.exe File name: c:\facebook Browse.exe
File type: Executable File
Mime Type: unknown/exe
C:\WINDOWS\trlrokgq File name: C:\WINDOWS\trlrokgq
C:\WINDOWS\mjulinav.dll File name: C:\WINDOWS\mjulinav.dll
File type: Dynamic link library
Mime Type: unknown/dll
%ProgramFiles%\random.exe File name: %ProgramFiles%\random.exe
File type: Executable File
Mime Type: unknown/exe
%AppData%\Bifrost\server.exe File name: %AppData%\Bifrost\server.exe
File type: Executable File
Mime Type: unknown/exe

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\NavigatingHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\random.exe"
Loading...