Troj/Nitfun-A is a Trojan that attempts to download and execute further files.

When first run, Troj/Nitfun-A injects itself into the process services.exe.

Troj/Nitfun-A attempts to download a file to the folder Temp\(random name)(random numbers)\, where (random name) is one of "image", "photo" or "index".


Troj/Nitfun-A may rename itself to dat.dll and may attempt to copy the file System\msasn1.dll to System\ms(random characters)as.dll and modify it.

More information can be found at this Sophos page.