Sophos

Troj/Agent-DN

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Detected by All Sophos products

Action

More Information

In order to run on system start, Troj/Agent-DN creates the following registry entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
REEGRUN = <path to EXE>

Troj/Agent-DN drops two additional components and modifies several registry entries under:

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3

The Trojan opens Internet Explorer and attempts to contact a remote site repeatedly every five seconds.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer