Troj/Agent-KPU is a Trojan for the Windows platform.
When Troj/Agent-KPU is installed the following files are created:
<System>\UsrClassEx.exe
<System>\UsrClassEx.exe.reg
<System>\kklog
<Temp>\Novel H1N1 Flu Situation Update.doc
<Temp>\doc.exe
<Temp>\make.exe
The files make.exe, doc.exe and UsrClassEx.exe are also detected as Troj/Agent-KPU. The file UsrClassEx.Exe.reg is a clean registry file. The file kklog is a clean log of stolen data. The file "Novel H1N1 Flu Situation Update.doc" is a clean Word document launched to hide the action of the Trojan.
The following registry entry is created to run UsrClassEx.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
UsrClassEx
<System>\UsrClassEx.exe