Win32/Agent.QMR [Threat Name] go to Threat

Win32/Agent.QMR [Threat Variant Name]

Category trojan
Size 12800 B
Detection created Dec 15, 2009
Detection database version 10213
Aliases Trojan-Dropper.Win32.Agent.bjpb (Kaspersky)
  TrojanDownloader:Win32/Bubnix.A (Microsoft)
  Trojan.MulDrop.53398 (Dr.Web)
Short description

Win32/Agent.QMR is a trojan which tries to download other malware from the Internet.

Installation

The trojan may create copies of itself in the folder:

  • %temp%

The following names are used:

  • %variable%.tmp

A string with variable content is used instead of %variable% .

Other information

The trojan contains a list of (3) URLs.


It tries to download several files from the addresses. The HTTP protocol is used.


These are stored in the following locations:

  • %system%\­drivers\­%random%.sys

A string with variable content is used instead of %random% .


Installs the following system drivers:

  • %system%\­drivers\­%random%.sys

Please enable Javascript to ensure correct displaying of this content and refresh this page.