Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 24 February 2005 12:14:29 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Agent-CH is a backdoor Trojan for the Windows platform.
Troj/Agent-CH will copy itself to a folder it creates named yemarvd within the Windows system folder as sysmon.exe.
Troj/Agent-CH will set the following registry entries to ensure that it run on Windows logon or startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
yemarvd
C:\WINDOWS\System32\yemarvd\sysmon.exe
Troj/Agent-CH will also set the following registry entry:
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main
yemarvdc
Troj/Agent-CH will also create a DLL in the Windows system folder named yemarvdn.dll. This file is currently detected by Sophos as Troj/Iyus-Fam.
Troj/Agent-CH will modify the HOSTS file in an attempt to block access to a predefined list of Anti-virus vendors. For example:
127.0.0.1 downloads1.kaspersky-labs.com
127.0.0.1 downloads2.kaspersky-labs.com
127.0.0.1 downloads3.kaspersky-labs.com
127.0.0.1 downloads4.kaspersky-labs.com
127.0.0.1 download.mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 update.symantec.com

