Threat behavior
TrojanDownloader:Win32/Agent.AHD is a trojan that drops additional malware and downloads and executes arbitrary files.
Installation
When executed, TrojanDownloader:Win32/Agent.AHD may drop the following files (file names used may differ between minor variants), for example:
- %programdir%\Temporary\wininstall.exe
- %programdir%\WinAble\winable.exe - detected as Trojan:Win32/Drastwor.A
The trojan then modifies the registry to run one of these files at each Windows start:
Adds value: "WinAble"
With data: "%programdir%\winable.exe"
To subkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
It makes several further modifications to the registry (including several to add an entry to the "Add/Remove Programs" list):
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow
*.starsdoor.com
Adds value: "remove"
With data: "ok"
To subkey: HKEY_CURRENT_USER\Software\WinAble
Adds value: "DisplayName"
With data: "WinAble"
To subkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\WinAble
Adds value: "UninstallString"
With data: ""%programdir%\WinAble\winable.exe" -uninstall"
To subkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\WinAble
Payload
Downloads and Executes Arbitrary Files
TrojanDownloader:Win32/Agent.AHD may download files from the following sites:
Downloaded files are saved to the Windows temp folder and executed from there.
Prevention