Troj/Agent-FD

Category: Viruses and Spyware
Type: Trojan
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Agent-FD is a Trojan for the Windows platform.

When Troj/Agent-FD is installed the following files are created:

<Windows system folder>\Filesys.ini
<Windows system folder>\ntfilesys.ini
<Windows system folder>\winupdate.exe

The following registry entry is changed to run winupdate.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe winupdate.exe

(the default value for this registry entry is "Explorer.exe" which causes the Microsoft file <Windows folder>\Explorer.exe to be run on startup).

The Trojan monitors this registry entry and restores it to the above setting if it is changed.

download Try Sophos products for free
Download now