Python/Agent.B [Threat Name] go to Threat

Python/Agent.B [Threat Variant Name]

Category trojan,worm
Size 3245461 B
Aliases Trojan.Win32.Agent.nesvxk (Kaspersky)
  Trojan:Win32/Dynamer!ac (Microsoft)
Short description

Python/Agent.B is a worm that spreads via removable media. The file is run-time compressed using PyInstaller .

Installation

When executed, the worm copies itself into the following location:

  • %systemdrive%\­users\­%username%\­AppData\­Roaming\­Microsoft\­Windows\­Start Menu\­Programs\­Startup\­Schosts.exe

This causes the worm to be executed on every system start.

Spreading on removable media

The worm copies itself into the root folders of removable drives using the following name:

  • movies.exe
Other information

The worm keeps various information in the following files:

  • %appdata%\­%variable%.txt

A string with variable content is used instead of %variable% .

Please enable Javascript to ensure correct displaying of this content and refresh this page.