Welcome to the Virus Encyclopedia of Panda Security.
It allows to get into the affected computer.
It uses stealth techniques to avoid being detected by the user.
It uses anti-monitoring techniques in order to prevent it being detected by antivirus companies.
It does not spread automatically using its own means.
|First detected on:||Oct. 1, 2006|
|Detection updated on:||Oct. 1, 2006|
|Yes, using TruPrevent Technologies
Agent.CTN is a Trojan, which although seemingly inoffensive, can actually carry out attacks and intrusions.
It uses stealth techniques to avoid being detected by the user:
- It injects itself in running processes.
It uses several methods in order to avoid detection by antivirus companies:
- It terminates its own execution if it detects that it is being executed in a virtual machine environment, such as VMWare or VirtualPC.
- It terminates its own execution if it detects that a memory dump program is running, such as Procdump.
- Its code is encrypted and it is only decrypted when it is going to run. Because of this, its code is not legible through a memory dump.
- It terminates its own execution if it detects that a debugging program is active.
Agent.CTN does not spread automatically using its own means. It needs an attacking user's intervention in order to reach the affected computer. The means of transmission used include, among others, floppy disks, CD-ROMs, email messages with attached files, Internet downloads, FTP, IRC channels, peer-to-peer (P2P) file sharing networks, etc.