Threat Description

Trojan-Downloader:W32/Agent.EYA

Details

Aliases:Trojan-Downloader:​W32/Agent.EYA, Agent.EYA
Category:Malware
Type:Trojan-Downloader
Platform:W32

Summary



This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files.



Removal


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.

More

You may wish to refer to the Support Community for further assistance. You also may also refer to General Removal Instructions for a general guide on alternative disinfection actions.



Technical Details



Trojan-Downloader:W32/Agent.EYA obtains malware from several links and executes them into the infected system.

This malware is related to Trojan-Spy:W32/Banker.

Activity

Upon execution, this Trojan downloads files from several links with the following format:

  • http://bl.fgs.org.tw/icons/.dat/[removed].exe

The files are saved in the Windows system directory with the following file names:

  • datta.exe - detected as Trojan-Spy.Win32.Banker.cxk
  • info1.exe - detected as Trojan-Spy.Win32.Banker.cxu
  • spoolsvw.exe - detected as Trojan-Spy.Win32.Banker.cxj
  • temp32.exe - detected as Trojan-Spy.Win32.Banker.cxu

The files are then executed.






SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Scan & clean your PC

F-Secure Online Scanner will scan and clean your PC in just a few minutes for free

Learn More