Troj/Agent-ODT

Category: Viruses and Spyware Protection available since:31 Jul 2010 11:01:05 (GMT)
Type: Trojan Last Updated:20 Dec 2010 15:49:34 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Agent-ODT is a Trojan for the Windows platform.

Troj/Agent-ODT includes functionality to:

- run automatically
- create batch scripts
- access the internet and communicate with a remote server via HTTP

Troj/Agent-ODT communicates via HTTP with the following locations:

instamfan . net

When Troj/Agent-ODT is installed it creates the file <User>\Application Data\Zina\ulkyo.exe.

The following registry entry is created to run ulkyo.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
{104F7FDF-9FFC-EB33-436E-5B66F5230848}
<User>\Application Data\Zina\ulkyo.exe

The following registry entries are set, affecting internet security:

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
1609
0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1406
0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
1609
0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
1609
0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
1406
0x00000000

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
1609
0x00000000

The following registry entry is set:

HKCU\Software\Microsoft\Internet Explorer\Privacy
CleanCookies
0x00000000

Registry entries are created under:

HKCU\Software\Microsoft\Yhzyu

download Try Sophos products for free
Download now