When run Troj/Agent-GYG drops two files in the Temp folder. These are detected as Troj/Agent-GXV and Mal/Behav-119.
Troj/Agent-GYG creates registry entries under the registry location:
HKCR\CLSID\{E25C29AB-12B9-4523-A53C-324B5FBA648C}
Troj/Agent-GYG also creates the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop
sysfile
<Infected filename>
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{E25C29AB-12B9-4523-A53C-324B5FBA648C}
""