March 13, 2010

9/9: Agent-HPU Trojan Disables Automatic Software Startup

Troj/Agent-HPU is a Trojan for the Windows platform.

Troj/Agent-HPU includes functionality to access the internet and communicate with a remote server via HTTP.

When first run Troj/Agent-HPU copies itself to \services.exe.

The following registry entry is created to run Troj/Agent-HPU on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run services
Windows\services.exe

Troj/Agent-HPU sets the following registry entries, disabling the automatic startup of other software:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess
Start 4

More information can be found at this Sophos page.

1
IT Offers

Partners