JS/Downloader.Agent

JS/Downloader.Agent Description

JS/Downloader.Agent is a detection for JavaScript files that may lead to the download and installation of additional malicious software onto the compromised computer. Affecting Windows, JS/Downloader.Agent typically invades a system due to affiliated trojans, modifying the browser settings to cause web-surfing activities to be diverted to a malicious domain.

Aliases: Trojan-PWS/W32.Agent.12800.C [nProtect], Password-Stealer [K7AntiVirus], Trojan/PSW.Agent.kyl [TheHacker], Trojan.PWS.Agent!i3GFpkLg3LY [VirusBuster], a variant of Win32/TrojanDownloader.Sality.G [NOD32], W32/Pws.BENS [F-Prot], W32/Pramro.C [Norman], Win32/Maazben!generic [TotalDefense], TSPY_AGENT.APW [TrendMicro-HouseCall], Win32:Sality-GR [Avast], Win32.Agent.kyl [eSafe], Trojan-PSW.Win32.Agent.kyl [Kaspersky], Trojan.Generic.5372981 [BitDefender], Troj/Dwnldr-HIP [Sophos] and TrojWare.Win32.PSW.Agent.kyl [Comodo].

Infected with JS/Downloader.Agent? Scan Your PC for Free

Download SpyHunter’s Spyware Scanner
to Detect JS/Downloader.Agent
* SpyHunter's free version is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter's malware removal tool to remove the malware threats. Read more on SpyHunter. If you no longer wish to have SpyHunter installed on your computer, follow these steps to uninstall SpyHunter.

Security Doesn't Let You Download SpyHunter or Access the Internet?


Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
  • Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
  • Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
  • Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in "Safe Mode with Networking" and install SpyHunter in Safe Mode.
  • IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.

If you still can't install SpyHunter? View other possible causes of installation issues.

Technical Information

File System Details

JS/Downloader.Agent creates the following file(s):
# File Name Size MD5 Detection Count
1 4c70249.sys 5,504 345d203dfd17a31c58d47400bf76b2ea 82
2 4bf9cba3.dll 216,951 0fcf8a43f7867974892ae2ce01ddeb84 81
3 8566f82e.dll 12,322 f126d887e9c03dee232bc7bdc7bed075 71
4 326xxx.dll 25,088 a064290bfcd2411cf058da4d0721cd1a 60
5 03518usc.dll 11,776 11e97e10b88a2bc7abf2c9f8a1c48b49 56
6 4138kou.dll 19,456 3a5098a7e404bc176f3f6b8155756a57 53
7 10417sys.dll 108,568 fb17fbf4416949da7bc1e41a728f0184 51
8 838.exe 35,840 67b514135d12ada992eaacea0dd7ea05 47
9 08223b03.dll 16,984 a992c4e43a9edf4a8ca6015f65b50bd3 44
10 122b901e.dll 14,941 51fe7eaff75951a23d0284a50995e68b 43
11 2ef0d734.dll 219,212 0d0e7fab4f9d9c9505386126df0d737b 42
12 49400W.exe 30,509 b55924e1f7808c555be832d347ff49a0 20
13 55551.dll 14,336 ec0702ddebf32fef040667e58123e234 17
14 7F1C46C1BD7F.dll 126,976 784e1bdc322601e631d5fe5e21ee151e 16
15 %TEMP%\winxrhcpb.exe 12,800 bd47bac8253e96e28b29f17ac48d4cc4 12
More files

Registry Details

JS/Downloader.Agent creates the following registry entry or registry entries:
HKEY..\..\{Value}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {744B92E0-B771-478B-80DC-CD9E77E5A8D8}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {E31C565C-F152-482D-A8C9-B0F6757539C9}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {1AF47292-E866-4E01-AF5C-C542C084925E}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {809E127E-78DA-4A71-AE5E-442A07833645}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {7BCAF997-6F01-4DC5-B5F4-395A89459721}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {A9019268-F38D-43F4-9E85-7443037BEDC6}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {E87B80D7-842E-40A7-86B4-76A0E5D76674}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {C704C461-5339-419A-9732-AD0054BD1110}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {A3083642-8392-48D2-BAB7-35075F86C3DD}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {5AD9956D-FEB3-4FF6-B719-00C02FCAD126}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {890F52A4-AB83-4C2B-94D5-36F36EB8F43D}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {5BE7E1FC-1503-4FA4-AD6A-A71BE13C9FA0}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {DCBC4DF7-09A8-42D0-BCF4-299F72F40EAD}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {52DD5A51-643A-419F-A202-C037912A7C5C}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {4CFA36E0-94A0-41C2-A656-6A10DF213015}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {77AC4257-6781-430B-80C1-BCA6D20C950F}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {8FD84462-BE2A-4E47-8CA0-E7AA55C62527}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {5041E91C-0B55-40C8-9E07-F592E5F5737E}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {697F9864-6D8E-4FD4-8686-7162C6FF67AA}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {C9FB7946-5871-4396-AAFE-9F4ABBFA00FA}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {C7577A8E-04AE-4551-B89A-200CF6F6EF7C}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {CBD32EAC-7ABA-4E81-90FA-9C2EA013A525}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {8FF71D28-9FC0-4D5D-9FF1-6E24F96DE4B7}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {47665FA5-FCF5-4444-B552-DF6549ECCA27}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {8BE76351-82E3-4E6F-B8EE-289C987DD602}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {815EDE81-767D-4636-80F5-141578667A98}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {06768E0B-AB67-451A-BC21-CD38C6194080}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {04250F54-2E41-4645-B5C3-54C0197B29C3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}
yuiabct
HBService32
WinSysW
WinSysM
The following CLSID's were found:
HKEY..\..\{CLSID Path}
{06768E0B-AB67-451A-BC21-CD38C6194080}
{09EB15FA-17D8-4D60-8598-3F549A848DF2}
{1638A53E-0627-45B6-AD57-E48B07AC20E0}
{1AF47292-E866-4E01-AF5C-C542C084925E}
{2200AF18-3A4F-4A5B-82F8-D8DC11B48597}
{3AAA8090-9D8D-4C2C-9D8C-B68BCB6A7BAA}
{3EA9EA6C-1E3B-475F-9266-2BE2C0D8788D}
{4150AB00-F8E9-4BFF-BDD4-EDA97BDD30FF}
{47665FA5-FCF5-4444-B552-DF6549ECCA27}
{526403AC-FEDD-4350-946A-BC0B8114C65A}
{52DD5A51-643A-419F-A202-C037912A7C5C}
{5B589B2C-54A2-4F41-9461-D26B6364D587}
{5BE7E1FC-1503-4FA4-AD6A-A71BE13C9FA0}
{697F9864-6D8E-4FD4-8686-7162C6FF67AA}
{6A6779ED-A95C-4946-8B3F-39F33E2D2140}
{735CA461-6C66-4BCA-8290-B0B27B8E9312}
{744B92E0-B771-478B-80DC-CD9E77E5A8D8}
{77AC4257-6781-430B-80C1-BCA6D20C950F}
{7BCAF997-6F01-4DC5-B5F4-395A89459721}
{809E127E-78DA-4A71-AE5E-442A07833645}
{890F52A4-AB83-4C2B-94D5-36F36EB8F43D}
{8BE76351-82E3-4E6F-B8EE-289C987DD602}
{8FD84462-BE2A-4E47-8CA0-E7AA55C62527}
{8FF71D28-9FC0-4D5D-9FF1-6E24F96DE4B7}
{94EE2B4F-5560-4392-AEFB-A4C98F9FE315}
{A9019268-F38D-43F4-9E85-7443037BEDC6}
{B38F5793-DFE3-4773-A3FF-8B9CC38FFB60}
{B8F4C7B3-74C8-4380-80B6-B66E5486B904}
{BEC07E68-F449-4E60-9D8B-052FE074410F}
{BF7243B5-E1E9-4E58-8803-23DC54C0879E}
{C0CD7A93-0E42-4593-962C-3AF1784B3064}
{C704C461-5339-419A-9732-AD0054BD1110}
{C7577A8E-04AE-4551-B89A-200CF6F6EF7C}
{C9FB7946-5871-4396-AAFE-9F4ABBFA00FA}
{DCBC4DF7-09A8-42D0-BCF4-299F72F40EAD}
{DFB3DAC5-B0B5-4B05-BFCF-FB42737778FA}
{E31C565C-F152-482D-A8C9-B0F6757539C9}
{E6ED0F88-01D3-435F-9913-5F30B83B84AC}
{E87B80D7-842E-40A7-86B4-76A0E5D76674}
{EECE5F2B-BD93-4477-8027-D3BE0EE7EB1A}
{F350EB80-6952-4B51-8F1C-CD2F29F456FE}
{F45D2DB6-1DC5-4C32-87F4-C47FBF0D8BA2}

Site Disclaimer

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.

IMPORTANT! To be able to proceed, you need to solve the following simple math.
Please leave these two fields as is:
What is 8 + 5 ?