About:
Troj/Agent-TBO is a Trojan for the Windows platform.
In this case, the malware won't work because of a mistake made by the bad guys. It won't run properly, so it is "defunct."
But the Trojan could cause problems for you if they manage to fix it manually.
Troj/Agent-TBO is usually distributed via email as a zipped attachment with a filename such as "Invoice_08.17.2011[...]rcod.exe" and an email subject of "Re: Corp. invoice from ATFT Corp."
When it's working properly, this malware includes functionality to:
- run automatically
- create auxiliary small files
- access the Internet and communicate with a remote server via HTTP
When Troj/Agent-TBO is installed it creates the files:
\Documents and Settings\Local Settings\Temp\8sRYNzaT.exe
\Documents and Settings\Local Settings\Temp\bh.tmp
bh.tmp contains the GUID: {F1944F1F-82F2-488C-8DF8-A5A0A85361AB}
Troj/Agent-TBO could establish a connection with following Internet location:
host-121.net51.sol.az
If the remote host does not respond the Trojan will try to delete itself.