Sophos

Troj/Agent-GGM

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 19 November 2007 18:43:00 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information


Troj/Agent-GGM is a Trojan for the Windows platform.

Troj/Agent-GGM contains functionality to access the internet and communicate with a remote server using HTTP.

When first run, Troj/Agent-GGM may create the following files:

<Temp>\Node00000000.ini - data
<Temp>\RarSFX0\resume.exe - detected as Troj/Agent-GGM
<Current Folder>\Node00000000.ini - data
<Windows>\wmupdate.exe - detected as Troj/Agent-GGM

The following registry entry is created to run wmupdate.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
wmupdate
<Windows>\wmupdate.exe

The following registry entries are set, affecting internet security:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\
StandardProfile\AuthorizedApplications\List
<Path to Trojan>\resume.exe
<Path to Trojan>\resume.exe:*:Enabled:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\
StandardProfile\IcmpSettings
AllowInboundEchoRequest
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer