Home / malwarePDF  

Trojan-Dropper:W32/Agent.DKIT


First posted on 25 August 2010.
Source: SecurityHome

Aliases :

There are no other names known for Trojan-Dropper:W32/Agent.DKIT.

Explanation :

A trojan that contains one or more malicious programs, which it will secretly install and execute.

Additional DetailsTrojan-Dropper:W32/Agent.DKIT drops files onto the affected system, then deletes itself.

Execution

On execution, Agent.DKIt drop files into the Windows or system32 folders:

€ %localappdata%\Windows Server\server.dat € %localappdata%\Windows Server\admin.txt € %windir%\system32\hlp.dat
Once these files are dropped, the trojan-dropper deletes itself from the system.

Registry Changes

During execution, the trojan-dropper creates the following mutexes:

€ Setup555 € Exists555

Last update 25 August 2010

 

TOP