9/9: Agent-HPU Trojan Disables Automatic Software Startup
Troj/Agent-HPU is a Trojan for the Windows platform.
Troj/Agent-HPU includes functionality to access the internet and communicate with a remote server via HTTP.
When first run Troj/Agent-HPU copies itself to The following registry entry is created to run Troj/Agent-HPU on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
services
Troj/Agent-HPU sets the following registry entries, disabling the automatic startup of other software:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess
More information can be found at this Sophos page.
Windows\services.exe
Start
4
