Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | December 2006 (4.12) |
| Protection available since | 2 November 2006 07:40:49 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/NetAtk-Gen is a Trojan for the Windows platform.
Troj/NetAtk-Gen runs continuously in the background allowing a remote intruder to gain access and control over the computer.
When Troj/NetAtk-Gen is installed the following files are created:
<System>\drivers\ndisfilter.sys
<System>\pfplg<3 letters>.dll
The file ndisfilter.sys is detected as Troj/NTRootK-AT and is used by the Trojan to hide the existence of the plugin dll (pfplg<3 letters>.dll).
The file ndisfilter.sys is registered as a new system driver service named "NdisFilter", with a display name of "NdisFilter" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\NdisFilter\
Troj/NetAtk-Gen has a plugin architecture allowing other malicious 'plugin' components to be loaded and used remotely.
