Sophos

Troj/Agent-GXS

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from June 2008 (4.30)
Protection available since 2 May 2008 08:19:09 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Agent-GXS is a Trojan for the Windows platform.

When first run,Troj/Agent-GXS copies itself to <Windows>\WindowsXP.exe and creates <Windows>\ftpa.ini.
  
Troj/Agent-GXS has the functionalities to:

-download files from preconfigured URLs.

-steal infomation then send to preconfigured URLs.

The following registry entry is changed to run <Windows>\WindowsXP.exe on startup:

  HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
  Shell
  Explorer.exe <Windows>\WindowsXP.exe

The following registry entry is created:

  HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
  DisableTaskMgr
  1

  HKCU\sRegPolicies+\Explorer
  NoChangeStartMenu
  1

  HKCU\sRegPolicies+\Explorer
  NoClose
  1

  HKCU\sRegPolicies+\Explorer
  NoLogoff
  1

The following registry entry is changed:

  HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess
  Start
  4

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer