Sophos

Troj/Agent-GPY

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from April 2008 (4.28)
Protection available since 18 February 2008 02:13:02 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Agent-GPY is a Trojan for the Windows platform.

When run, the following files are created:

<System>\NTSpool.exe
<System>\rar.exe
<System>\WinSecure.exe

The file rar.exe is not malicious and can be safely removed. The files NTSpool.exe and WinSecure.exe are detected as Troj/Agent-GPY.

The following registry entries are created to run NTSpool.exe and WinSecure.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
NTSpool
NTSpool.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Windows Security Tool
WinSecure.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer