Win32/Agent.UJK [Threat Name] go to Threat

Win32/Agent.UJK [Threat Variant Name]

Category trojan
Size 114688 B
Detection created Jan 10, 2013
Detection database version 7880
Aliases Trojan:Win32/Redyms.A (Microsoft)
  Trojan.Win32.Genome.ajtql (Kaspersky)
Short description

Win32/Agent.UJK is a trojan that redirects results of online search engines to specific web sites.

Installation

When executed the trojan copies itself in the following locations:

  • %appdata%\­%guid%79\­%variable%.exe

A string with variable content is used instead of %guid%, %variable% .


In order to be executed on every system start, the trojan sets the following Registry entries:

  • [HKEY_CURRENT_USER\­SOFTWARE\­Microsoft\­Windows\­CurrentVersion\­Policies\­Explorer\­Run]
    • "%variable%" = "%appdata%\­%guid%79\­%variable%.exe"
  • [HKEY_CURRENT_USER\­SOFTWARE\­Microsoft\­Windows\­CurrentVersion\­Run]
    • "Adobe CS Manager"="%APPDATA%\­%GUID%79\­%RND%.exe"

The trojan may set the following Registry entries:

  • [HKEY_CURRENT_USER\­SOFTWARE\­Adobe\­CSXS.2.5]
    • "LogLevel" = "1"
    • "tLastM_Reader" = ""

The trojan creates and runs a new thread with its own program code in all running processes.


After the installation is complete, the trojan deletes the original executable file.

Other information

Win32/Agent.UJK is a trojan that redirects results of online search engines to specific web sites.


The trojan affects the behavior of the following applications:

  • Inernet Explorer
  • Mozilla Firefox
  • Google Chrome
  • Opera
  • Safari
  • Netscape
  • Avant
  • Maxthon
  • Mozilla Suite

The trojan hooks the following Windows APIs:

  • WSPSend (mswsock.dll)
  • WSPRecv (mswsock.dll)
  • WSPCloseSocket (mswsock.dll)
  • ZwResumeThread (ntdll.dll)
  • ZwClose (ntdll.dll)

It can execute the following operations:

  • update itself to a newer version
  • shut down/restart the computer
  • modify network traffic

Please enable Javascript to ensure correct displaying of this content and refresh this page.