Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 5 July 2007 00:58:04 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/RKAgen-A is a Trojan for the Windows platform.
Troj/RKAgen-A drops the file <Windows>\system32\windbg48.sys. This file is detected as Troj/RKAgen-Fam. This file is registered as a new system driver service with a display name of "windbg48" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\windbg48\
