Sonicwall Signatures


Go to All Categories list.

Geral.NFI is a Trojan. A Trojan is a program that pretends to have a valid use, but in fact modifies the user's computer in malicious way. Trojans do not replicate or spread to other computers. Geral.NFI is compressed using the executable packer and its file size is 13,568 bytes. It also changes Windows registry:
  • Creates key "HKLM\System\CurrentControlSet\Services\SAMPLE".
  • Creates value "ImagePath"="C:\sample.sys" in key "HKLM\System\CurrentControlSet\Services\SAMPLE".
  • Creates value "DisplayName"="SAMPLE" in key "HKLM\System\CurrentControlSet\Services\SAMPLE".
Geral.NFI configures following services on NT based machines:
  • Creates service "SAMPLE (SAMPLE)" as "C:\sample.sys".

Relevant Information