Home Malware Programs Trojans Win32/TrojanDownloader.Agent.QXN

Win32/TrojanDownloader.Agent.QXN

Posted: December 1, 2011

Threat Metric

Ranking: 16,741
Threat Level: 9/10
Infected PCs: 2,808
First Seen: December 1, 2011
Last Seen: September 7, 2023
OS(es) Affected: Windows

Win32/TrojanDownloader.Agent.QXN is both a Trojan dropper and a worm that installs additional types of malicious files while Win32/TrojanDownloader.Agent.QXN seeks to spread via removable and/or networked drives. Win32/TrojanDownloader.Agent.QXN uses deception both in its installation method, via a fake package delivery e-mail, and during the course of its attacks (by concealing itself inside of a fake Windows process). Symptoms of Win32/TrojanDownloader.Agent.QXN can vary due to its configurable payload, and SpywareRemove.com malware experts recommend that you trust an accurate anti-malware product to detect and remove Win32/TrojanDownloader.Agent.QXN. Until this is done, you should be wary about sharing drives, folders or other resources with other computers, since Win32/TrojanDownloader.Agent.QXN may use these resources for its own distribution.

Win32/TrojanDownloader.Agent.QXN - Beware This Secret Santa

Although Win32/TrojanDownloader.Agent.QXN may also be distributed by other methods (such as e-mail messages about fake ACH payments), the latest Win32/TrojanDownloader.Agent.QXN attacks have been linked to fake package delivery notifications that are spammed to arbitrary e-mail accounts. These professional-looking e-mail messages, supposedly from the Canada Post, claim that a package delivery failed because no one was there to receive it. The Win32/TrojanDownloader.Agent.QXN e-mail even contains a legitimate Canada Post link above a fake link that contains a .pif-based delivery mechanism for Win32/TrojanDownloader.Agent.QXN. SpywareRemove.com malware research team has noted that this fake link has been masked so that its URL appears to be similar to the legitimate link, even if the actual destination is completely-different. In general, it's recommended that you avoid launching .pif programs that aren't from trustworthy sources, since they can be exploited to open program files.

If you do click this link and run the resulting file (which may be launched automatically, depending on how much or how little your security settings stand between you and this action) Win32/TrojanDownloader.Agent.QXN will infect your PC and proceed to unload its rather non-jolly payload of malicious programs.

Don't Fret if Your Holiday Spirit is Tainted by Win32/TrojanDownloader.Agent.QXN

An active Win32/TrojanDownloader.Agent.QXN poses the following threats to any Windows PC:

  • Win32/TrojanDownloader.Agent.QXN may spread via removable drive devices or local networks by abusing Autorun.inf vulnerabilities. You should prevent other computers from accessing resources on your PC or shared removable drives since Win32/TrojanDownloader.Agent.QXN will install itself without consent.
  • Besides its worm functions, Win32/TrojanDownloader.Agent.QXN also shows some signs of Trojan characteristics. Win32/TrojanDownloader.Agent.QXN will attempt to make contact with and download files from malicious sites like randomcrappy.com, seriouslyfucked.ru and karabasdobryak.eu. SpywareRemove.com malware researchers warn that Win32/TrojanDownloader.Agent.QXN may install high-level PC threats such as rootkits, keyloggers, banking Trojans or rogue anti-virus programs.

Because Win32/TrojanDownloader.Agent.QXN hides itself in the form of a fake svchost.exe file, you should be prepared to uproot a Win32/TrojanDownloader.Agent.QXN infection with advanced anti-malware software. Depending on the brand of software that you use to remove Win32/TrojanDownloader.Agent.QXN, Win32/TrojanDownloader.Agent.QXN may be detected by one of its aliases: Trojan/Win32.FakeAV, Troj/Bredo-KN, Worm:Win32/Gamarue.B, Trojan.DownLoader5.886 or Trojan.Win32.Yakes.glu.

Aliases

Trj/CI.A [Panda]Generic26.RHX [AVG]W32/Agent.QXN!tr.dldr [Fortinet]Trojan.SuspectCRC [Ikarus]Downloader/Win32.Deliver [AhnLab-V3]TR/Offend.kdv.459967 [AntiVir]Trojan.DownLoader5.17279 [DrWeb]UnclassifiedMalware [Comodo]Troj/FakeAV-EWH [Sophos]Trojan.Generic.KDV.459967 [BitDefender]Win32:Downloader-LSC [Trj] [Avast]Trojan.Gen [Symantec]Win32/TrojanDownloader.Agent.QXN [NOD32]Riskware [K7AntiVirus]Artemis!7AD1DF533141 [McAfee]
More aliases (22)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\Local Settings\Temp\811eff71008e7ee1.exe File name: 811eff71008e7ee1.exe
Size: 42.49 KB (42496 bytes)
MD5: 7ad1df533141d3dcafee7008b267a53c
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: December 13, 2011
setup_406.exe File name: setup_406.exe
Size: 2.03 MB (2035152 bytes)
MD5: 7225bdcfd7afab35640ed22d17292aac
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 8, 2021
Loading...