Sophos

Sophos blogs

Troj/Agent-HR

Aliases
  • Trojan.Win32.Agent.hr
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 24 November 2005 02:40:39 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Agent-HR is a Trojan for the Windows platform.

Troj/Agent-HR disables the mouse, contol panel, registry editor and property manager. The Trojan sets certain restrictions for the Internet Explorer and delete registry entries.

The Trojan copies itself as crcss.exe in the Windows System folder. The following registry entries are created to run crcss.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Client Server Control Process
<path to the Trojan>

The Trojan creates the following registry entries:

HKCU\Software\Microsoft\Internet Explorer\Infodelivery\Restrictions
NoBrowserSaveWebComplete
1

HKCU\Software\Microsoft\Internet Explorer\Restrictions
NoBrowserSaveAs
1

HKCU\Software\Microsoft\Internet Explorer\Restrictions
NoPrinting
1

HKCU\Software\Microsoft\Internet Explorer\Restrictions
NoSelectDownloadDir
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoControlPanel
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoDrives
9

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoRun
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoViewOnDrive
9

HKCU\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\2\3\0
NodeSlot
a

HKLM\SOFTWARE\0verNight
0verNight v.1.7 - written by ki

HKLM\SOFTWARE\0verNight
FOR MY ...

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
NoAdminPage
1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
NoProfilePage
1

HKLM\SOFTWARE\Policies\Windows NT\SystemRestore
DisableConfig
1

HKLM\SOFTWARE\Policies\Windows NT\SystemRestore
DisableSR
1

HKLMSOFTWARE\Policies\Windows\Installer
DisableMSI
2

HKLMSOFTWARE\Policies\Windows\Installer
DisableMedia
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer