Sophos

Troj/Agent-GWA

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from June 2008 (4.30)
Protection available since 13 April 2008 15:40:24 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Agent-GWA is a Trojan for the Windows platform.

Troj/Agent-GWA includes functionality to download, install and run new software.

Troj/Agent-GWA attempts to download files to:

<Temp>\Plus.exe
<Temp>\flash.exe
<System>\doit.exe

When first run doit.exe creates the file <System>\native.exe which it adds to the following registry entry to run at startup:

HKLM\SYSTEM\CurrentControlSet\Control\Session Manager
BootExecute

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer