Antivirus and Security Software from Sophos

Sophos blogs

Troj/Agent-HZ

Aliases
  • Trojan-PSW.Win32.Agent.an
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Protection available since 27 December 2005 05:20:24 (GMT)
Last updated 2 January 2006 16:06:47 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Agent-HZ is a password stealing Trojan for the Windows platform.

Troj/Agent-HZ has the functionalities to:

- steal email server passwords
- send notification messages to remote locations
- access the Internet and communicate with a remote server via HTTP

When run, Troj/Agent-HZ copies itself to <System>\svchostss.exe

When run, Troj/Agent-HZ creates and runs the file <System>\helpersvchostss.exe. The file helpersvchostss.exe is detected by Sophos as Troj/Agent-HZ.

When run, Troj/Agent-HZ sets the following registry entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WindowsUpdatesvchostss
svchostss.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer