Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 14 May 2008 13:44:59 (GMT) |
| Last updated | 6 June 2008 14:30:58 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Agent-GZK attempts to edit websites to promote a target website.
Troj/Agent-GZK consists of three components:
<System>\jdk-1_5_0_19-windows-i391-pp\jav.bat
<System>\jdk-1_5_0_19-windows-i391-pp\js.exe
<System>\jdk-1_5_0_19-windows-i391-pp\dc.class
The files js.exe and dc.class are both detected as Troj/Agent-GZK.
Troj/Agent-GZK installs itself in the registry so it autoruns at startup with the following registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
"Java (VM) v6.9"
"C:\WINDOWS\System32\jdk-1_5_0_19-windows-i391-pp\jav.bat"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
"Java (VM) v6.9"
"C:\WINDOWS\System32\jdk-1_5_0_19-windows-i391-pp\jav.bat"

