Trojan.Agent.FKIA

Alias: Worm.Win32.AutoRun.svl (Kaspersky), Spy-Agent.bw (McAfee), WORM_AUTORUN.BWQ (Trend), Win32/AutoRun.FakeAlert.AD (NOD)
Length: 26,112 byte
Date of appearance/update: 2008 November
Category: Trojan


Incidence: High
Danger level: High
More informations:

The messages have a variable German subject, and the German language contents of e-mails are also variable. The Trojan can be found in zip file attached to e-mails.

After execution the Trojan creates a binary file, which mimics one of Windows' system files, and registers itself into the registry to autostart this file at every system boot. The Trojan also drops a rootkit component, which is detected by Virusbuster products as Rootkit.Autorun.Gen.10.

The Trojan also copies itself to the root directory of available drives, and creates an appropriate autorun.inf file to ensure that it will be executed when opening the drive.

The trojan attempts to download further malware components from the internet.