Threat Database Trojans Trojan.Spy.Agent

Trojan.Spy.Agent

By CagedTech in Trojans

Threat Scorecard

Ranking: 246
Threat Level: 80 % (High)
Infected Computers: 572,252
First Seen: July 24, 2009
Last Seen: May 13, 2024
OS(es) Affected: Windows

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Ikarus Gen.Trojan.Heur
DrWeb DLOADER.Trojan
Avast Win32:Malware-gen
McAfee Artemis!D951CF99EEC5
Panda Lion.II
AhnLab-V3 BAT/Rootkit
Antiy-AVL Trojan/Shell.Agent
AntiVir TR/Rootkit.Linux.Agent.SK
DrWeb Unix.ShellSpy
Kaspersky Trojan-Spy.Shell.Agent.a
Avast VBS:Malware-gen
Symantec Infostealer
F-Prot Unix/Agent.SK
NOD32 Linux/Shell.Agent.A
K7AntiVirus Trojan

SpyHunter Detects & Remove Trojan.Spy.Agent

File System Details

Trojan.Spy.Agent may create the following file(s):
# File Name MD5 Detections
1. winmonprocessmonitor.sys 290389e59ca9fe99ce1779f41f26d645 223,366
2. winmon.sys 4ef0c39e632279d7b3672d2efc071e5b 100,430
3. winmon.sys 0abf2951ad6d55b34be49004261c4a41 1,142
4. winmon.sys 533af2f594b5c4536ec8cf93abaec514 391
5. WinmonProcessMonitor.sys.dvs cc32dc3e78ddc9c36e0cb286f255a999 293
6. 688606ed20b933123345a197a174110fdd92940ae3b67484b2a6f7ef001470ca c74978bf8dbff9da9d3104fc3fe03cec 273
7. winmonprocessmonitor.sys d64b955e7e24dea146a70fbc671c5eb9 182
8. svhosts.exe 0d8febf9cdd19417d92cff61c39b77a6 61
9. MSIMG32.dll 1d0b4f048fffd884b81814b452126a7b 54
10. asz$audio.exe fff6fe8e5091420d284da376b5641781 24
11. MSIMG32.dll 23842e945f3a8234a07fa08b309c1732 21
12. svhosts.exe 6f86be05e0d9a74455b42e87ecf2c651 19
13. MSIMG32.dll b4aaa9ff5cfe3d6e26fd985f2ec70507 17
14. hbmwqlq.exe 90a74c3fa4357f9c4ebb2cb665cdd86a 15
15. svhosts.exe ee7c3f90b02824e913e017e975b180dd 6
16. sexurbs.exe 2b530b9a6833c8ae3b9e5282ccdeaf79 6
17. MARRIO~1.EXE 3dba917e0b2610600ac5d99d63c6211f 5
18. NYQBIDP.exe a6e351d7be60c0b518738badc8b1f5b3 5
19. MSIMG32.dll c80e521cbc443b8c1e0c9f7a879e5f18 4
20. svhosts.exe 93937438037b43c45ec9c8442831f985 3
21. MSIMG32.dll bab03273be6dc5f0b4449238f182214e 3
22. svhosts.exe 11157ba34879eeb01e844a3c2031ddcd 1
23. svhosts.exe d649dd3f37a4debf42f730b3ce627eb7 1
24. MSIMG32.dll 4c6098312f9cb57168c6392b6ef6dec5 1
25. ivrewkgc.exe d07e48313d4459b9f6c6cb047dfd8baf 1
26. uhhxnxyzzxwx.exe 763408f6eacbb3770dc425f52d375481 1
27. Cleated.exe d30191b8a128a44ea7acae6df8a7b797 1
More files

Registry Details

Trojan.Spy.Agent may create the following registry entry or registry entries:
File name without path
RE[B]Ell.bat
Regexp file mask
%ALLUSERSPROFILE%\ccleaner.exe
%ALLUSERSPROFILE%\Windows Server\wserver.exe
%APPDATA%\datZZ~.dat
%APPDATA%\dvdcss\dvdcss.exe
%APPDATA%\Kaspersky Internet Security 2017\explorers.exe
%APPDATA%\Kaspersky Internet Security 2017\spoolsvc.exe
%APPDATA%\Kaspersky Internet Security 2017\svhost.exe
%APPDATA%\Kaspersky Internet Security 2017\Taskhosts.exe
%APPDATA%\WebCounter\WebCounter.exe
%COMMONPROGRAMFILES%\finder.exe
%COMMONPROGRAMFILES(x86)%\finder.exe
%LOCALAPPDATA%\Jaxx\jaxxsrv.exe
%LOCALAPPDATA%\Microsoft Windows\svchost.exe
%LOCALAPPDATA%\Packages\SandboxieRpcSc.exe
%LOCALAPPDATA%\Packages\svchost.exe
%USERPROFILE%\gupd.exe
%WINDIR%\Media\Long\certsvc.exe
%WINDIR%\system32\drivers\ibinldr.sys
%WINDIR%\System32\drivers\WinmonProcessMonitor.sys
%WINDIR%\SysWOW64\Windows Server\wserver.exe

Directories

Trojan.Spy.Agent may create the following directory or directories:

%ALLUSERSPROFILE%\googieupdater
%TEMP%\NetPlatform\WorkDir
%WINDIR%\cmdacoBin

Related Posts

Trending

Most Viewed

Loading...