Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | October 2008 (4.34) |
| Protection available since | 6 September 2008 17:31:21 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Agent-HPC is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.
Troj/Agent-HPC includes functionality to access the internet and communicate with a remote server via HTTP.
When first run Troj/Agent-HPC copies itself to randomly generated filenames in the Windows system folder.
A registry entry such of the following form is created to run the Trojan on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<randomly generated string>
<path to copy of Trojan>
The Trojan is registered as a new system driver service with randomly chosen name and display name. The service will start automatically during system startup. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\<randomly generated string>
