Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | December 2008 (4.36) |
| Protection available since | 7 October 2008 20:03:16 (GMT) |
| Last updated | 8 October 2008 14:52:58 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
When first run, Troj/Agent-HVW copies itself to the following location:
<Windows>\service.exe
Troj/Agent-HVW attempts to download files from the internet.
The following registry entries are created in order to start Troj/Agent-HVW when Windows starts:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Messenger Service
service.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
Messenger Service
service.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
Messenger Service
service.exe
The following registry entries may be created in order to disable Task Manager and editing of the registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\system
DisableTaskMgr
0x00000001
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\system
DisableRegistrytools
0x00000001
