Troj/Agent-BMF is a backdoor Trojan which allows a remote intruder to gain
access and control over the computer.
Troj/Agent-BMF includes functionality to access the internet and communicate
with a remote server via HTTP.
When Troj/Agent-BMF is installed the following files are created:
<Temp>\ddos.exe
<Temp>\load44(2).exe
<Temp>\loader.exe
<Temp>\ope4.bat
<System>\Not
<System>\html
<System>\public
<System>\requested
<System>\xffanl.exe
The file load44(2).exe is detected as Troj/Dowadv-C and the file loader.exe is
detected as Troj/SpyDldr-E.
The following registry entries are created to run xffanl.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
svcroot
<System>\xffanl.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
svcroot
<System>\xffanl.exe
The following registry entry is changed to run xffanl.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe xffanl.exe
(the default value for this registry entry is "Explorer.exe" which causes the
Microsoft file <Windows>\Explorer.exe to be run on startup).