Threat Encyclopedia

Selected viruses, spyware, and other threats: sorted alphabetically

Short description
Win32/Agent.PHT is a trojan that is used for spam distribution.
Installation
When executed, the trojan copies itself into the following location:
  • %system%\services.exe (26112 B)
In order to be executed on every system start, the trojan sets the following Registry entries:
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
    CurrentVersion\Run]
    "servises" = "%system%\servises.exe"
  • [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
    Run]
    "servises" = "%system%\servises.exe"
Other information
Win32/Agent.PHT is a trojan that is used for spam distribution.

The trojan is sent data and commands from a remote computer or the Internet. The trojan contains a list of (1) URL addresses. The HTTP protocol is used.

The trojan can download and execute a file from the Internet.