RTKT_AGENT_00000003.TOMA

 Analysis by: Karl Dominguez

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 REPORTED INFECTION:
 SYSTEM IMPACT RATING:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted: Yes

  • In the wild: Yes

  OVERVIEW

This is the Trend Micro heuristic detection for suspicious files that manifest similar behavior and characteristics of rootkit component files of other malware.

If your Trend Micro product detects a file under this detection name, do not execute the file. Delete it immediately especially if it came from an untrusted or an unknown source (e.g., a Web site of doubtful nature). However, if you have reason to believe that the detected file is non-malicious, you can submit a sample for analysis. Detailed analysis will be done on submitted samples, and corresponding removal instructions will be provided, if necessary.

This Trojan may be dropped by other malware.

  TECHNICAL DETAILS

File Size:

Varies

File Type:

SYS

Initial Samples Received Date:

20 Jan 2011

Arrival Details

This Trojan may be dropped by other malware.