Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | March 2007 (4.15) |
| Protection available since | 1 February 2007 13:26:57 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Agent-EBK is a keylogging Trojan with rootkit functionality.
When Troj/Agent-EBK is first installed, it creates the files
<System>\Ygyfrmrh.d1l
<System>\Ygyfrmrh.dll
<System>\Ygyfrmrh.sys
These files are also detected as Troj/Agent-EBK.
Ygyfrmrh.sys is installed as a system driver, providing stealth functionality in order to hide all three of the installed files.
Troj/Agent-EBK monitors keyboard activity and periodically sends all logged keypresses to a remote location via HTTP forms.
