Troj/Agent-ZA is a Trojan which runs in the background as a service process and attempts to allow unauthorised access to the computer.
The Trojan creates an entry in the registry at the following location to run itself on system restart:
HKLM\SYSTEM\ControlSet001\Services\__NS_Service\ImagePath
The Trojan creates the following registry entries:
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY___NS_SERVICE\0000\
Service= __NS_Service
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY___NS_SERVICE\0000\
DeviceDesc= Network Security Service
Troj/Agent-ZA also deletes the registry entry
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\
AppInit_DLLs .