Home Malware Programs Trojans Trojan Horse Agent_r.AUQ

Trojan Horse Agent_r.AUQ

Posted: December 7, 2011

Threat Metric

Threat Level: 9/10
Infected PCs: 61
First Seen: December 7, 2011
Last Seen: March 25, 2024
OS(es) Affected: Windows

Trojan Horse Agent_r.AUQ is a malicious Trojan infection which depends on a trick of as password-protection of its files. Trojan Horse Agent_r.AUQ can also apply password access to other files. Some files password-encoded by Trojan Horse Agent_r.AUQ are critically important for PC users as Trojan Horse Agent_r.AUQ is able to lock frequently used objects. Use a genuine and powerful anti-malware tool to remove Trojan Horse Agent_r.AUQ.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\WINDOWS\system.ini File name: C:\WINDOWS\system.ini
Mime Type: unknown/ini
Group: Malware file
C:\WINDOWS\system32\lsass.exe File name: C:\WINDOWS\system32\lsass.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\WINDOWS\system32\svchost.exe(Trojan Horse Agent_r.AUQ) File name: C:\WINDOWS\system32\svchost.exe(Trojan Horse Agent_r.AUQ)
Mime Type: unknown/AUQ)
Group: Malware file
C:\Program Files\CyberLink\Shared Files\RichVideo.exe File name: C:\Program Files\CyberLink\Shared Files\RichVideo.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Program Files\Java\jre6\bin\jqs.exe File name: C:\Program Files\Java\jre6\bin\jqs.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE File name: C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
File type: Executable File
Mime Type: unknown/EXE
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ".exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dllHKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe
Loading...