Sophos

Troj/Enfal-A

Aliases
  • Trojan.Win32.Enfal.d
  • Enfal
  • WORM_AGENT.DJI
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from September 2006 (4.09)
Protection available since 7 August 2006 08:43:49 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Enfal-A is a Trojan for the Windows platform.

Troj/Enfal-A includes functionality to:
- inject multiple threads into the process EXPLORER.EXE
- download code from the internet

When run Troj/Enfal-A copies itself to <System>\dismgnt.exe and <System>\winkrnl.exe.

Troj/Enfal-A modifies the following registry entry to run itself on Windows Logon:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<System>\DisMgnt.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer