Sophos

Sophos blogs

Troj/Agent-GYG

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 6 May 2008 15:11:32 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

When run Troj/Agent-GYG drops two files in the Temp folder. These are detected as Troj/Agent-GXV and Mal/Behav-119.

Troj/Agent-GYG creates registry entries under the registry location:

HKCR\CLSID\{E25C29AB-12B9-4523-A53C-324B5FBA648C}

Troj/Agent-GYG also creates the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop
sysfile
<Infected filename>

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{E25C29AB-12B9-4523-A53C-324B5FBA648C}
""

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer