Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | January 2008 (4.25) |
| Protection available since | 19 November 2007 18:43:00 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Agent-GGM is a Trojan for the Windows platform.
Troj/Agent-GGM contains functionality to access the internet and communicate with a remote server using HTTP.
When first run, Troj/Agent-GGM may create the following files:
<Temp>\Node00000000.ini - data
<Temp>\RarSFX0\resume.exe - detected as Troj/Agent-GGM
<Current Folder>\Node00000000.ini - data
<Windows>\wmupdate.exe - detected as Troj/Agent-GGM
The following registry entry is created to run wmupdate.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
wmupdate
<Windows>\wmupdate.exe
The following registry entries are set, affecting internet security:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\
StandardProfile\AuthorizedApplications\List
<Path to Trojan>\resume.exe
<Path to Trojan>\resume.exe:*:Enabled:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\
StandardProfile\IcmpSettings
AllowInboundEchoRequest
1
