Sophos

Troj/Agent-GOI

Aliases
  • Win32/Agent.NPH
  • Email-Worm.Win32.Agent.cl
  • Backdoor:Win32/Oderoor.gen!B
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from March 2008 (4.27)
Protection available since 1 February 2008 11:11:40 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Agent-GOI is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.

When first run Troj/Agent-GOI copies itself to <System>\bqrlyv.exe.

The following registry entry is created to run bqrlyv.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<random 1>
<System>\<random 1>.exe

The file bqrlyv.exe is registered as a new system driver service named "random 2", with a display name of "Print Spooler Service" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\<random 2>

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer