TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
TROJ_AGENT.KAQ
Overview

Malware type: Trojan

Aliases: No Alias Found

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

Medium

Distribution potential:

Low

Description: 

This Trojan arrives in the system as a file downloaded by the following malwares:

It drops a .DLL file that is also detected by Trend Micro as TROJ_AGENT.KAQ. The said .DLL file is then injected into running processes on the affected system. It then deletes itself after executing.

It creates a registry key and entry to enable its automatic execution at every system startup.

It attempts to connect to a certain URL to update itself. It deletes the HOSTS file. It sents the system date and time to January 1, 1999 at 8:01 AM.

For additional information about this threat, see:
Solution
Technical Details

Description created: Mar. 2, 2008 11:58:30 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.