Sophos

Troj/Agent-KZ

Aliases
  • Trojan.Win32.Agent.kz
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from January 2006 (4.01)
Protection available since 25 November 2005 14:26:45 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Agent-KZ is a downloader Trojan for the Windows platform.

When Troj/Agent-KZ is installed it creates the file <System>\mscom32.dll.

The file mscom32.dll is registered as a COM object and ShellExecute hook,
creating registry entries under:

HKCR\CLSID\(23246306-E6FB-4869-88ED-B4D4B5041EC1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\

Troj/Agent-KZ may modify an infected computer's Hosts file to redirect attempted
access of certain security websites to a pre-specified address.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer