Win32/TrojanDropper.Agent.OJS [Threat Name] go to Threat

Win32/TrojanDropper.Agent.OJS [Threat Variant Name]

Category trojan
Size 69632 B
Detection created Oct 15, 2009
Detection database version 4510
Aliases Trojan-Dropper.Win32.Agent.bkwe (Kaspersky)
  Trojan:Win32/Trafog!rts (Microsoft)
  Clicker.WYE (AVG)
Short description

The trojan is designed to artificially generate traffic to certain Internet sites.

Installation

When executed, the trojan creates the following files:

  • %windir%\­%number%.exe (49152 B)

The %number% represents a random number.


In order to be executed on every system start, the trojan sets the following Registry entry:

  • [HKEY_LOCAL_MACHINE\­SOFTWARE\­Microsoft\­CurrentVersion\­Run]
    • "Windows Explorer" = "%windir%\­%variable%.exe"
Other information

The trojan acquires data and commands from a remote computer or the Internet.


The trojan contains an URL address. The HTTP protocol is used.


The trojan is designed to artificially generate traffic to certain Internet sites.


The trojan sends requests to simulate clicks on banner advertisements, to inflate web counter statistics etc.


The trojan attempts to delete the following files:

  • %windir%\­Media\­Windows XP Start.wav
  • %windir%\­Media\­start.wav

The trojan may create the following files:

  • %temp%\­%variable1%.html
  • %temp%\­%variable2%\­%variable3%.html

The %variable1-3% represents a random number.

Please enable Javascript to ensure correct displaying of this content and refresh this page.