Trojan-Downloader.Win32.Agent.bvz
This Trojan is a Windows PE EXE file. It is 41,472 bytes in size. InstallationWhen installing, the Trojan copies its executable file to the Windows system directory: %System%\ntos.exe In order to ensure that the Trojan is launched automatically when the system is rebooted, the Trojan adds a link to its executable file in the system registry: [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "userinit" = "%System%\ntos.exe"
The Trojan tracks user activity in Internet Explorer. If https://onlineeast.bankofamerica.com is opened/ used, the Trojan will periodically take screenshots of the user's desktop and upload them to the remote malicious user's FTP server.
If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
|
|||||||||||