Trojan-Downloader.Agent!sd5 Description
Trojan-Downloader.Agent!sd5 is considered to be a mischievous Trojan, which penetrates into an affected computer system without a user's consent or knowledge via the security exploits. Trojan-Downloader.Agent!sd5 enables remote attackers gain access to your PC to steal your personal information. Trojan-Downloader.Agent!sd5 will disable your security tools and make changes to your PC system settings. Trojan-Downloader.Agent!sd5 will also download additional malware components to your machine. Trojan-Downloader.Agent!sd5 has to be deleted immediately after detection.
Technical Information
File System Details
Trojan-Downloader.Agent!sd5 creates the following file(s):
# | File Name | Size | MD5 |
---|---|---|---|
1 | %Temp%\FineTop_FT75.exe | ||
2 | c:\DelUS.bat | ||
3 | %ProgramFiles%\FineTop\FineTop.exe | ||
4 | %AppData%\Microsoft\FineTop\FineTopUDF.exe | ||
5 | %ProgramFiles%\FineTop\1 | ||
6 | file.exe | 489,472 | 0e38a0539109d573868593caaaa2752c |
Registry Details
Trojan-Downloader.Agent!sd5 creates the following registry entry or registry entries:
RegistryKey
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F1AACA8D-4899-4D6C-B360-403A5A20B5D2}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3E54C6DC-A2C6-404C-A36F-DE346281B3A7}\1.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CBF53489-AD8D-4637-965A-413861EEC7CF}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CBF53489-AD8D-4637-965A-413861EEC7CF}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3E54C6DC-A2C6-404C-A36F-DE346281B3A7}\1.0\FLAGS
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FineTop.TopBand\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FineTop.TopBand.1\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F1AACA8D-4899-4D6C-B360-403A5A20B5D2}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3E54C6DC-A2C6-404C-A36F-DE346281B3A7}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CBF53489-AD8D-4637-965A-413861EEC7CF}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CBF53489-AD8D-4637-965A-413861EEC7CF}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F1AACA8D-4899-4D6C-B360-403A5A20B5D2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FineTop.TopBand
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FineTop.TopBand.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F1AACA8D-4899-4D6C-B360-403A5A20B5D2}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3E54C6DC-A2C6-404C-A36F-DE346281B3A7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3E54C6DC-A2C6-404C-A36F-DE346281B3A7}\1.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CBF53489-AD8D-4637-965A-413861EEC7CF}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CBF53489-AD8D-4637-965A-413861EEC7CF}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3E54C6DC-A2C6-404C-A36F-DE346281B3A7}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FineTop.TopBand\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CBF53489-AD8D-4637-965A-413861EEC7CF}
Site Disclaimer
Enigmasoftware.com is not associated, affiliated, sponsored or owned
by the malware creators or distributors mentioned on this article. This article should NOT be
mistaken or confused in being associated in any way with the promotion or endorsement of malware.
Our intent is to provide information that will educate computer users on how to detect, and ultimately
remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on
this article.
This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.
This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.