Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | June 2008 (4.30) |
| Protection available since | 22 April 2008 19:05:15 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/RKAgen-E is a Trojan for the Windows platform.
When Troj/RKAgen-E is installed the following files are created:
<Temp>\girls_1024x768.jpeg
<Temp>\my_fotos.exe
<System>\drivers\grande48.sys
The file girls_1024x768.jpeg is harmless.
The file my_fotos.exe is detected as Troj/RKAgen-E.
The file grande48.sys is detected as Troj/RKAgen-Fam.
The file grande48.sys is registered as a new system driver service named "grande48", with a display name of "grande48" and a startup type of automatic, so that it is started automatically during system startup.
Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\grande48
