Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Included in our products from | January 2006 (4.01) |
| Protection available since | 7 November 2005 11:47:14 (GMT) |
| Last updated | 25 November 2005 13:35:31 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Agent-EY is a downloader and information stealer Trojan for the Windows platform.
The Trojan will copy itself to the Windows system folder as "perfmnt.exe" .
The Trojan creates the following registry entries:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe
Debugger
<path of Trojan EXE>
Troj/Agent-EY uses Internet Explorer to open a predefined URL without the user's knowledge, and download a file as "update.php" to the Temporary Internet Files folder.
The Trojan collects certain information and submits it to a predefined URL.
