Threat Database Trojans Troj/Agent-GGJ

Troj/Agent-GGJ

By Domesticus in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 9
First Seen: December 1, 2011
Last Seen: October 18, 2020
OS(es) Affected: Windows

Troj/Agent-GGJ is a dangerous Trojan that targets Windows PCs. Troj/Agent-GGJ enables cybercriminals to remotely access and monitor the affected computer. Once installed on a corrupted PC system, Troj/Agent-GGJ adds malicious files and registry entries. Troj/Agent-GGJ also adds its startup registry entry so that it can start each time you boot up your PC. Troj/Agent-GGJ has a functionality to download a code from the web. Uninstall Troj/Agent-GGJ immediately after detection.

File System Details

Troj/Agent-GGJ may create the following file(s):
# File Name Detections
1. \svchost.exe
2. \wmupdate.exe

Registry Details

Troj/Agent-GGJ may create the following registry entry or registry entries:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\RarSFX0\AcrobatChs.exe\\RarSFX\AcrobatChs.exe:*:Enabled:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\svchost.exe\\svchost.exe:*:Enabled:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\IcmpSettings\AllowInboundEchoRequest\1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wmupdate

Trending

Most Viewed

Loading...