Need help? Ask the community or hire an expert.
Go to Avira Answers
Virus:TR/Dldr.Harnig.AZ.A
Date discovered:03/01/2006
Type:Trojan
Subtype:Downloader
In the wild:Yes
Reported Infections:Low
Distribution Potential:Low
Damage Potential:Low to medium
Static file:Yes
File size:3.097 Bytes
MD5 checksum:035C4CC69D72DF46126DCE27381857F5
VDF version:6.33.00.77

 General Method of propagation:
   • No own spreading routine


Aliases:
   •  Symantec: Download.Trojan
   •  Kaspersky: Trojan-Downloader.Win32.Agent.ach
   •  Bitdefender: Trojan.Downloader.Agent.AR


Platforms / OS:
   • Windows 95
   • Windows 98
   • Windows 98 SE
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP


Side effects:
   • Downloads malicious files

 Files It copies itself to the following location:
   • %WINDIR%\sysldr32.exe




It tries to download some files:

– The location is the following:
   • http://72.36.244.185/0030/**********
It is saved on the local hard drive under: %TEMPDIR%\dmx%hex number%.tmp Furthermore this file gets executed after it was fully downloaded. At the time of writing this file was not online for further investigation.

– The location is the following:
   • http://72.36.244.185/0030/**********
It is saved on the local hard drive under: %TEMPDIR%\dmx%hex number%.tmp Furthermore this file gets executed after it was fully downloaded. At the time of writing this file was not online for further investigation.

– The location is the following:
   • http://72.36.244.185/0030/**********
It is saved on the local hard drive under: %TEMPDIR%\dmx%hex number%.tmp Furthermore this file gets executed after it was fully downloaded.

 Registry The following registry key is added in order to run the process after reboot:

– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   • "SystemLoader" = "%WINDIR%\sysldr32.exe"

 Backdoor Contact server:
All of the following:
   • http://72.36.244.185/0030/in**********
   • http://72.36.244.185/0030/out**********

This is done via the HTTP GET request on a PHP script.

 File details Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with a runtime packer.

Description inserted by Nicolae Begnescu on Wednesday, January 4, 2006
Description updated by Andrei Ivanes on Friday, March 24, 2006

Back . . . .