When Troj/Agent-HFZ is installed the following files are created:
<System>\ntos.exe - copy of Troj/Agent-HFZ
<System>\wsnpoem\audio.dll - empty file, can be safely deleted
<System>\wsnpoem\video.dll - empty file, can be safely deleted
The following registry entry is changed to run ntos.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<System>\ntos.exe,