Troj/Agent-TH is a Trojan for the Windows platform.
Troj/Agent-TH includes functionality to access the internet and communicate with a remote server via HTTP.
Troj/Agent-TH may insert itself into Explorer.exe process space.
When first run Troj/Agent-TH copies itself to <System>\systemupd.exe.
The following registry entries are set to run systemupd.exe at start up:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WindowsAudio
<System>\systemupd.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
*WindowsAudio
<System>\systemupd.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
WindowsAudio
<System>\systemupd.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*WindowsAudio
<System>\systemupd.exe