Sophos

Troj/Agent-GVY

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2008 (4.30)
Protection available since 13 April 2008 03:28:07 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Agent-GVY is a Trojan for the Windows platform.

When run Troj/Agent-GVY copies itself to <System>\dmhfk.exe and sets the following registry entries under:

HKCU\Software\Microsoft\Windows\CurrentVersion\_r
kfhmd

HKCU\Software\Microsoft\Windows\CurrentVersion
dmhfk.exe

Troj/Agent-GVY also registers itself as a system service with the display name of "Windows Management Service" and a startup type of automatic. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\Windows Management Service\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer