Threat Database Trojans Trojan Horse Agent_r.ARN

Trojan Horse Agent_r.ARN

By SpideyMan in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 1
First Seen: November 22, 2011
Last Seen: October 29, 2020
OS(es) Affected: Windows

Trojan Horse Agent_r.ARN contains a harmful payload that allows criminals to profit in various ways from infecting your computer system. However, the characteristic that sets apart Trojan Horse Agent_r.ARN from other malware threats is its use of an unwanted musical tune which will pop up out of nowhere to annoy its victim. The presence of Trojan Horse Agent_r.ARN on a computer system will usually manifest itself with this music of unknown origin coming out of the victim's speakers. This quirk is something secondary to Trojan Horse Agent_r.ARN's main malicious effect; this Trojan will make a computer system become extremely slow and unstable. As Trojan Horse Agent_r.ARN takes over an infected computer system, the infected computer becomes unresponsive and will start to exhibit strange behaviors. Victims of the Trojan Horse Agent_r.ARN will often find that their search engines have been disabled or altered, and that their computer's start screen has been changed or is not displayed anymore. Needless to say, the presence of Trojan Horse Agent_r.ARN on your hard drive is certainly a cause for worry. According to ESG security researchers, the removal of Trojan Horse Agent_r.ARN should be a top priority. Failure to act quickly can result in the loss of the ability to run programs or even start up your computer system.
 

Dealing with Trojan Horse Agent_r.ARN

While it is possible to remove Trojan Horse Agent_r.ARN manually, ESG malware analysts recommend using a reliable anti-malware application to scan your hard drives, remove Trojan Horse Agent_r.ARN and restore your system settings automatically. The Trojan Horse Agent_r.ARN infection has often been linked to malicious components that make the removal of Trojan Horse Agent_r.ARN much more difficult. Some ways in which Trojan Horse Agent_r.ARN can protect itself is by blocking access to the Internet, blocking access to popular anti-malware programs and crashing the system whenever removal is attempted. However, most of the time self-defense mechanisms can be bypassed by starting up Windows in Safe Mode. Trojan Horse Agent_r.ARN makes changes to the Windows Registry that allows Trojan Horse Agent_r.ARN to start up automatically whenever Windows is launched. Starting up Windows in Safe Mode (by pressing the key F8 during start up and choosing Safe Mode from a list of options) stops Trojan Horse Agent_r.ARN from starting up automatically. This allows you to gain unimpeded access to your security applications, in order to proceed with automatic removal of the Trojan Horse Agent_r.ARN infection.

File System Details

Trojan Horse Agent_r.ARN may create the following file(s):
# File Name Detections
1. C:\Program Files\Java\jre6\bin\jqs.exe
2. C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
3. C:\Program Files\CyberLink\Shared Files\RichVideo.exe
4. C:\WINDOWS\system32\lsass.exe
5. C:\WINDOWS\system.ini
6. C:\WINDOWS\system32\svchost.exe(Agent_r.ARN)
7. C:\WINDOWS\system32\drivers\etc\hosts

Registry Details

Trojan Horse Agent_r.ARN may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
HKEY_LOCAL_MACHINE Winlogon: Shell – (Explorer.exe) -C:\WINDOWS\explorer.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ".exe"

Trending

Most Viewed

Loading...