Sophos

Sophos blogs

Troj/Agent-GWA

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Protection available since 13 April 2008 15:40:24 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Agent-GWA is a Trojan for the Windows platform.

Troj/Agent-GWA includes functionality to download, install and run new software.

Troj/Agent-GWA attempts to download files to:

<Temp>\Plus.exe
<Temp>\flash.exe
<System>\doit.exe

When first run doit.exe creates the file <System>\native.exe which it adds to the following registry entry to run at startup:

HKLM\SYSTEM\CurrentControlSet\Control\Session Manager
BootExecute

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer