Sophos

Troj/Agent-XC

Aliases
  • Trojan-Downloader.Win32.Agent.xc
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2005 (4.00)
Protection available since 15 October 2005 15:42:29 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Agent-XC is a Trojan for the Windows platform.

When first run Troj/Agent-XC copies itself to <System>\csmsv.exe and creates the following files:

<Temp>\248.bat
<Temp>\315.bat

Both of these files are harmless on their own and can be safely deleted.

Troj/Agent-XC will attempt to give itself unrestricted access through the firewall running on the infected computer. The Trojan wil then use this access to look for other open ports on the local network, which may be reported to a remote user.

Troj/Agent-XC has the ability to download and execute files from remote URLs.

The following registry entries are created to run csmsv.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ControlServiceMgr
csmsv.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ControlServiceMgr
csmsv.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer