Sophos

Troj/Enfal-B

Aliases
  • Worm.Win32.Agent.i
  • Enfal.dr
  • Win32/Agent.I
  • WORM_AGENT.DJI
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from November 2006 (4.11)
Protection available since 19 September 2006 14:47:16 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Enfal-B is a backdoor Trojan for the Windows platform.

Troj/Enfal-B includes functionality to access the internet and communicate with a remote server via HTTP.

When Troj/Enfal-B is installed the following files are created:
<System>\DisMgnt.exe
<System>\NtApi.exe
<System>\Winkrnl.exe
<System>\ace\temp\kb791024.l0g

where NtApi.exe is an archiver application.

Troj/Enfal-B injects multiple threads into the process EXPLORER.EXE.

The files DisMgnt.exe and Winkrnl.exe are detected as Troj/Enfal-A.

Registry entries are set as follows:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
0

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe,<System>\<original Trojan filename>

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer