Troj/Agent-ECU is a backdoor Trojan for the Windows platform.
Troj/Agent-ECU includes the functionality to access the internet and communicate with a remote server via HTTP.
When Troj/Agent-ECU is installed it creates the file <System>\ntos.exe.
The following registry entry is changed to run ntos.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<System>\ntos.exe,
The following registry entry is set:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
pathx
pathname of the Trojan executable