Troj/Agent-ALLA

Category: Viruses and SpywareProtection available since:04 Feb 2015 10:59:13 (GMT)
Type: TrojanLast Updated:04 Feb 2015 10:59:13 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Troj/Agent-ALLA include:

Example 1

File Information

Size
812K
SHA-1
662c16c667ea611dcd04e04e9ea845c90bccf213
MD5
d9e877c9d256256a5d8b37073f5f8cd8
CRC-32
88334303
File type
PK ZIP archive
First seen
2015-02-03

Other vendor detection

Avira
TR/Agent.593416

Example 2

File Information

Size
580K
SHA-1
87668d14910c1e1bb8bbea0c6363f76e664dcd09
MD5
f58a4369b8176edbde4396dc977c9008
CRC-32
29e7ac5e
File type
Windows executable
First seen
2015-01-28

Other vendor detection

Avira
TR/Agent.593416

Example 3

File Information

Size
1.2M
SHA-1
c3d8a548fa0525e1e55aa592e14303fc6964d28d
MD5
f16dff8ec8702518471f637eb5313ab2
CRC-32
390fbe21
File type
Windows executable
First seen
2015-01-29

Other vendor detection

Avira
TR/Agent.1192744

Runtime Analysis

Dropped Files
  • c:\Documents and Settings\test user\Local Settings\Temp\Acr8D14.tmp
    Size
    358
    SHA-1
    3e115005772d8918b8c2e3ba3c79caba82aa79ba
    MD5
    2bd1250028ffaa48eed1e990ea3d1a15
    CRC-32
    bcb6ba7c
    File type
    Adobe Portable Document Format (PDF)
    First seen
    2015-02-03
  • c:\Documents and Settings\test user\Local Settings\Temp\hppscan854.pdf
    Size
    182K
    SHA-1
    c8fe2296565c211e019cdad3918a5736d4b12d44
    MD5
    93176df76e351b3ea829e0e6c6832bdf
    CRC-32
    6f79f534
    File type
    Adobe Portable Document Format (PDF)
    First seen
    2015-02-03
  • c:\Documents and Settings\test user\Local Settings\Temp\reader_sl.exe
    Size
    580K
    SHA-1
    87668d14910c1e1bb8bbea0c6363f76e664dcd09
    MD5
    f58a4369b8176edbde4396dc977c9008
    CRC-32
    29e7ac5e
    File type
    Windows executable
    First seen
    2015-01-28
Processes Created
  • c:\docume~1\support\locals~1\temp\reader_sl.exe
  • c:\program files\adobe\reader 8.0\reader\acrord32.exe