Win32/Agent.NCH [Threat Name] go to Threat

Win32/Agent.NCH [Threat Variant Name]

Category trojan,virus,worm
Detection created Aug 11, 2006
Detection database version 1969
Aliases Backdoor.Win32.Agent.ajq (Kaspersky)
  Infostealer.JiangHu (Symantec)
Short description

Win32/Agent.NCH is a trojan that steals sensitive information. The trojan can send the information to a remote machine.

Installation

When executed, the trojan creates the following files:

  • security.exe
  • winlogin.exe
  • userspi.dll

The trojan registers itself as a system service using the following name:

  • ServerAC
Information stealing

The trojan collects information related to the on-line game Eudemons Online .


The trojan can send the information to a remote machine. The HTTP protocol is used.


The trojan can download and execute a file from the Internet.

Please enable Javascript to ensure correct displaying of this content and refresh this page.