This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files.
Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.
Trojan-Downloader:W32/Agent.EYA obtains malware from several links and executes them into the infected system.
This malware is related to Trojan-Spy:W32/Banker.
Upon execution, this Trojan downloads files from several links with the following format:
The files are saved in the Windows system directory with the following file names:
- datta.exe - detected as Trojan-Spy.Win32.Banker.cxk
- info1.exe - detected as Trojan-Spy.Win32.Banker.cxu
- spoolsvw.exe - detected as Trojan-Spy.Win32.Banker.cxj
- temp32.exe - detected as Trojan-Spy.Win32.Banker.cxu
The files are then executed.