Sophos

Troj/Agent-DZY

Aliases
  • TSPY_LEGMIR.AOS
  • Rootkit.Win32.Agent.dc
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from March 2007 (4.15)
Protection available since 17 January 2007 06:01:18 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Agent-DZY is a DLL component helper Trojan for the Windows platform.

Once installed, Troj/Dropper-MZ may create the file <System>\drivers\KWatch1.sys. The file KWatch1.sys is also detected as Troj/Agent-DZY.

Troj/Agent-DZY also installs the file KWatch1.sys as a service "KWatch1" and creates registry entries under:

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_KWATCH1\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer