Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Included in our products from | August 2008 (4.32) |
| Protection available since | 4 July 2008 15:45:52 (GMT) |
| Last updated | 4 July 2008 18:39:24 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Agent-HEM is a Trojan for the Windows platform.
Troj/Agent-HEM includes functionality to access the internet and communicate with a remote server via HTTP.
When Troj/Agent-HEM is installed the following files are created:
<System>\<random>.exe
<System>\<random>.dll
<System>\<random>
The following registry entries are created to run code exported by <random>.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\<random>
Startup
<random>
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\<random>
DLLName
<random>.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\<random>
Impersonate
0
