W32/Agent.AIUP is a Trojan that will infect Windows systems.

The Trojan may be dropped by other malware or may be downloaded from remote website by other malware. It may also be downloaded unknowingly by a user while visiting malicious Website.

Upon execution, the Trojan drops the following files:

elyyxee in the %Program Files% folder.

This Trojan modifies registry at the following locations to load itself during each startup:

HKEY_CLASSES_ROOT\CLSID\{2197CE7A-96FF-68E2-B7FA-086702C5B3A5}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run.

It also modifies registry at the following locations:

HKEY_CURRENT_USER\Software\Uninstall\LPo5WLhicC
HKEY_CURRENT_USER\Software\wkey
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

The Trojan tries to connect to the Internet to download an updated copy of itself.

More information can be found at this Proland Software page.