SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Geral.NFI
Geral.NFI is a Trojan. A Trojan is a program that pretends to have a valid use, but in fact modifies the user's computer in malicious way. Trojans do not replicate or spread to other computers. Geral.NFI is compressed using the executable packer and its file size is 13,568 bytes. It also changes Windows registry:
  • Creates key "HKLM\System\CurrentControlSet\Services\SAMPLE".
  • Creates value "ImagePath"="C:\sample.sys" in key "HKLM\System\CurrentControlSet\Services\SAMPLE".
  • Creates value "DisplayName"="SAMPLE" in key "HKLM\System\CurrentControlSet\Services\SAMPLE".
Geral.NFI configures following services on NT based machines:
  • Creates service "SAMPLE (SAMPLE)" as "C:\sample.sys".


Relevant Information