Sophos

Troj/Agent-FV

Aliases
  • Trojan-Clicker.Win32.Small.jc
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 14 December 2005 14:24:53 (GMT)
Last updated 7 January 2006 00:21:33 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/Agent-FV is a Trojan for the Windows platform.

Troj/Agent-FV is capable of spying on a user's browsing habits, modifying Internet Explorer settings, downloading further executables and displaying popup advertisements.

When Troj/Agent-FV is installed the following files are created:

<System>\iewatch.exe
<System>\kaboom.dll

The following registry entry is created to run iewatch.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IEAgent update check
<System>\iewatch.exe

The file kaboom.dll is registered as a COM object and Browser Helper Object (BHO) for Microsoft Internet Explorer, creating registry entries under:

HKCR\CLSID\(CC56A1F3-9B83-45FF-8CB6-D58959492F0F)
HKCR\Interface\(88B67E52-A8D4-44AF-A199-DEE96469B7AF)
HKCR\Kaboom.IEagent\
HKCR\Kaboom.IEagent.1\
HKCR\TypeLib\(B73EF4A8-B8B1-4683-8D21-AA1C1A46CAD7)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\(CC56A1F3-9B83-45FF-8CB6-D58959492F0F)

Registry entries are created under:

HKLM\SOFTWARE\Microsoft\IEAgent\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer