Home Malware Programs Malware VirTool:WinNT/Exforel.A

VirTool:WinNT/Exforel.A

Posted: December 7, 2012

Threat Metric

Ranking: 2,435
Threat Level: 1/10
Infected PCs: 5,352
First Seen: December 7, 2012
Last Seen: October 17, 2023
OS(es) Affected: Windows

VirTool:WinNT/Exforel.A is a malware threat that enables attackers to gain remote unauthorized access and control of the affected computer. Once installed and executed on the targeted PC, VirTool:WinNT/Exforel.A makes system changes by adding potentially malicious files. VirTool:WinNT/Exforel.A is installed as a driver by other components of the Exforel family. Attackers use VirTool:WinNT/Exforel.A to perform numerous different actions on the victimized computer system. VirTool:WinNT/Exforel.A
uploads, downloads files and executes files. VirTool:WinNT/Exforel.A also routs TCP/IP traffic. VirTool:WinNT/Exforel.A uses low-level network function hooks, at the NDIS (Network Driver Interface Specification) level, and may not be spotted by common user-mode applications.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



ndisxapi.sys File name: ndisxapi.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
Loading...