W32/Agent.AVR!bdr

description-logoAnalysis

W32/Agent.AVR!bdr - 05-12-07


General Info:

This threat is a "PE" executable file, with file size 4608, with file compression: UPX

Network/Internet:

  • Connects to Server: + HTTP

Files:

  • Copies itself to: + undefinedSystemRootundefined/undefinedWinDirundefined

Installation to System:

  • When run, it copies itself to:
    - it copies itself in the \undefinedSystemundefined\ directory as msping.exe, - it doesn't delete the initial file, - it stays idle until it has internet access.
  • And creates these registry entries:
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\msping.exe = undefinedSystemundefined\msping.exe

More Info:

To remove the malware, please, follow these instructions : - locate and remove the file msping.exe which is contained in the undefinedSystemundefined directory ; - locate and delete the registry entry HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\msping.exe.

Telemetry logoTelemetry