Troj/Agent-ODT is a Trojan for the Windows platform.
Troj/Agent-ODT includes functionality to:
- run automatically
- create batch scripts
- access the internet and communicate with a remote server via HTTP
Troj/Agent-ODT communicates via HTTP with the following locations:
instamfan . net
When Troj/Agent-ODT is installed it creates the file <User>\Application Data\Zina\ulkyo.exe.
The following registry entry is created to run ulkyo.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
{104F7FDF-9FFC-EB33-436E-5B66F5230848}
<User>\Application Data\Zina\ulkyo.exe
The following registry entries are set, affecting internet security:
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
1609
0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1406
0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1609
0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
1609
0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
1406
0x00000000
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
1609
0x00000000
The following registry entry is set:
HKCU\Software\Microsoft\Internet Explorer\Privacy
CleanCookies
0x00000000
Registry entries are created under:
HKCU\Software\Microsoft\Yhzyu