Sophos

W32/Agent-GTZ

Aliases
  • BKDR_HUPIGON.LQC
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2008 (4.29)
Protection available since 26 March 2008 18:47:50 (GMT)
Detected by All Sophos products

Action

More Information

W32/Agent-GTZ is a worm for the Windows platform.

W32/Agent-GTZ includes functionality to access the internet and communicate with a remote server via HTTP.

When W32/Agent-GTZ is installed it creates the file <Program Files>\Internet Explorer\iewd.exe.

The file iewd.exe is detected as Mal/EncPk-AW.

The file iewd.exe is registered as a new system driver service named "rdhxacd", with a display name of "Remcte Procedure Transfer" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\rdhxacd

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer