MSIL/Agent.RY [Threat Name] go to Threat

MSIL/Agent.RY [Threat Variant Name]

Category trojan,worm
Size 395264 B
Detection created Jun 13, 2014
Detection database version 17627
Aliases Trojan.Win32.Agent.nfaebb (Kaspersky)
Short description

MSIL/Agent.RY is a worm that spreads via removable media.

Installation

When executed, the worm copies itself into the following location:

  • %startup%\­usbMonitor.exe

This causes the worm to be executed on every system start.

Spreading on removable media

The worm copies itself into the root folders of removable drives using the following name:

  • %removabledrivevolumelabel%.exe
Other information

The worm moves the content of the following folders (source, destination):

  • %removabledrive%\­%existingfolder%, %removabledrive%\­%removabledrivevolumelabel%\­%existingfolder%

The worm moves the following files (source, destination):

  • %removabledrive%\­%existingfile%, %removabledrive%\­%removabledrivevolumelabel%\­%existingfile%

The %removabledrive%\%removabledrivevolumelabel%\ folder may have the System (S) and Hidden (H) attributes set in attempt to hide the folder in Windows Explorer.


The worm may execute the following commands:

  • explorer.exe %removabledrive%\­%removabledrivevolumelabel%\­

Please enable Javascript to ensure correct displaying of this content and refresh this page.