Sophos

Troj/Agent-GUV

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from May 2008 (4.29)
Protection available since 2 April 2008 13:56:27 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Agent-GUV is a Trojan for the Windows platform.

When first run Troj/Agent-GUV copies itself to <System>\wins\setup\msmgrs.exe and creates the file <Startup>\ntdll.lnk.

Troj/Agent-GUV sets the following registry entries, disabling the automatic startup of other software:

HKLM\SYSTEM\CurrentControlSet\Services\srservice
Start
4

The following registry entry is set:

HKCU\Software\Microsoft\Windows\CurrentVersion\Settings
LocationOld
<pathname of the Trojan executable>

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer