Home Malware Programs Trojans VirTool:Win32/Injector.gen!AG

VirTool:Win32/Injector.gen!AG

Posted: November 5, 2009

VirTool:Win32/Injector.gen!AG is a malicious backdoor trojan horse that runs in the background and allows remote access to the compromised system. VirTool:Win32/Injector.gen!AG, which is also known as Win-Trojan/Agent.147456.AK, attempts to propagate by exploiting local network shares. VirTool:Win32/Injector.gen!AG will also attempt to join a predefined IRC server and channel stolen data in order to participate in distributed denial-of-service (DDoS) attack. The DDoS attacks will attempt to make the computer unavailable to its intended users. It is recommended that VirTool:Win32/Injector.gen!AG be removed immediately with a good anti-spyware application.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Bifrost

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Bifrost][HKEY_LOCAL_MACHINE\SOFTWARE\Bifrost][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}]
Loading...