Sophos

Troj/Agent-HVW

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2008 (4.36)
Protection available since 7 October 2008 20:03:16 (GMT)
Last updated 8 October 2008 14:52:58 (GMT)
Detected by All Sophos products

Action

More Information

When first run, Troj/Agent-HVW copies itself to the following location:

<Windows>\service.exe

Troj/Agent-HVW attempts to download files from the internet.

The following registry entries are created in order to start Troj/Agent-HVW when Windows starts:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Messenger Service
service.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
Messenger Service
service.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
Messenger Service
service.exe

The following registry entries may be created in order to disable Task Manager and editing of the registry:

HKLM\Software\Microsoft\Windows\CurrentVersion\policies\system
DisableTaskMgr
0x00000001

HKLM\Software\Microsoft\Windows\CurrentVersion\policies\system
DisableRegistrytools
0x00000001

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer