Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | November 2008 (4.35) |
| Protection available since | 6 October 2008 19:48:33 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
When first run, Troj/Agent-HVP copies itself to the following location:
<System>\systeminit.exe
Troj/Agent-HVP also overwrites the following Windows system file with a malicious version:
<System>\drivers\beep.sys
The following registry entry is created in order to ensure that this file is loaded even in safe mode:
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal
beep.sys
beep
