Sophos

Troj/Agent-FZ

Aliases
  • Trojan-Downloader.Win32.Agent.fz
  • TROJ_AGENT.ZD
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2005 (4.00)
Protection available since 20 October 2005 00:43:24 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Agent-FZ is a Trojan for the Windows platform.

Troj/Agent-FZ includes functionality to access the internet and communicate with a remote server via HTTP.

When first run Troj/Agent-FZ copies itself to <Windows>\dcf5678.exe.

The following registry entry is created to run dcf5678.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
AdPopup
<Windows>\dcf5678.exe

The following registry entries are set, affecting internet security:

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\boxsearch.net
*
2

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\brdatahost.com
*
2

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer