In order to run on system start, Troj/Agent-DN creates the following registry entry:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
REEGRUN = <path to EXE>
Troj/Agent-DN drops two additional components and modifies several registry entries under:
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
The Trojan opens Internet Explorer and attempts to contact a remote site repeatedly every five seconds.