Troj/Agent-HEM is a Trojan for the Windows platform.
Troj/Agent-HEM includes functionality to access the internet and communicate with a remote server via HTTP.
When Troj/Agent-HEM is installed the following files are created:
<System>\<random>.exe
<System>\<random>.dll
<System>\<random>
The following registry entries are created to run code exported by <random>.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\<random>
Startup
<random>
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\<random>
DLLName
<random>.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\<random>
Impersonate
0