Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 15 May 2006 04:57:48 (GMT) |
| Last updated | 24 May 2006 13:59:23 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Opnis-D is a Trojan for the Windows platform.
When run, Troj/Opnis-D creates the following files:
<Temp>/~dr?.tmp
<System>\ieen445F8764.dll
<System>\ntms445F8764.dll
<System>\olea445F8764.exe
<System>\plgwiz32.dll
<System>\usrs445F8764.dll
The "~dr?.tmp" file is a rootkit that provides stealing ability for the Trojan.
The Trojan interferes with the following processes:
ccapp.exe
firefox.exe
iexplore.exe
mpftray.exe
opera.exe
outpost.exe
services.exe
smc.exe
svchost.exe
zapro.exe
zlclient.exe
Troj/Opnis-D allows backdoor access to the infected computer.
The Trojan has the ability to communicate with a remote server via HTTP.
Registry entries are created under:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\plgwiz32
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_<COMPUTER NAME><DIGITS>\
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
"ieen445F8764.dll usrs445F8764.dll"
