Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
In order to run on system start, Troj/Agent-DN creates the following registry entry:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
REEGRUN = <path to EXE>
Troj/Agent-DN drops two additional components and modifies several registry entries under:
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
The Trojan opens Internet Explorer and attempts to contact a remote site repeatedly every five seconds.
