Sophos

Troj/Agent-GUO

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2008 (4.29)
Protection available since 30 March 2008 22:32:59 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Agent-GUO is a Trojan for the Windows platform.

When first run Troj/Agent-GUO copies itself to <Windows>\help\F3C74E3FA248.exe and creates the following file:

<Windows>\help\F3C74E3FA248.dll

The file F3C74E3FA248.dll is detected as Mal/LineDLL-B.

The file F3C74E3FA248.dll is registered as a COM object and shell extension, creating registry entries under:

HKCR\CLSID\(1DBD6574-D6D0-4782-94C3-69619E719765)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\(1DBD6574-D6D0-4782-94C3-69619E719765)

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer