Virus

W32/Agent.BU!tr

Analysis

W32/Agent.BU!tr - 05-12-31


General Info:

This threat is a "PE" executable file, with file size 62658

Files:

  • Drop files: ".exe" + ".dll"

Installation to System:

  • Drops the following files:
    undefinedSystemFolderundefined\ibm00001.exe undefinedSystemFolderundefined\ibm00001.dll undefinedSystemFolderundefined\ibm00002.exe
  • And creates these registry entries:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Shell = ""undefinedSystemFolderundefined\ibm00001.exe""

More Info:

This trojan drops W32/Zapchast.AD!tr and W32/Small.DG!tr.