Win32/Spammer.Agent.J [Threat Name] go to Threat

Win32/Spammer.Agent.J [Threat Variant Name]

Category trojan
Size 74240 B
Detection created Apr 19, 2011
Detection database version 6055
Aliases Worm:Win32/Koobface.AV (Microsoft)
Short description

Win32/Spammer.Agent.J is a trojan that posts messages to user profiles on social networks. The file is run-time compressed using UPX .

Installation

When executed, the trojan copies itself into the following location:

  • %temp%\­lolsbm2.exe

In order to be executed on every system start, the trojan sets the following Registry entry:

  • [HKEY_LOCAL_MACHINE\­SOFTWARE\­Microsoft\­Windows\­CurrentVersion\­Run]
    • "lolsb" = "%temp%\­lolsbm2.exe"
Other information

The trojan acquires data and commands from a remote computer or the Internet.


The trojan contains a list of (58) URLs. The HTTP protocol is used.


Win32/Spammer.Agent.J is a trojan that posts messages to user profiles on social networks.


The trojan connects to the AOL Lifestream network.


The trojan may create the following files:

  • %windir%\­aop

It can execute the following operations:

  • remove itself from the infected computer

Please enable Javascript to ensure correct displaying of this content and refresh this page.