Sophos

Troj/Nebuler-D

Aliases
  • Packed.Win32.Klone.g
  • BackDoor-CVT
  • TROJ_KLONE.AB
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2007 (4.19)
Protection available since 25 August 2006 14:21:44 (GMT)
Last updated 19 May 2007 07:00:08 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Nebuler-D is a Trojan for the Windows platform.
Troj/Nebuler-D gathers details relating to dialup services and sends collected information to a remote site via HTTP. The Trojan may inject code into other processes in an attempt to remain hidden.

Troj/Nebuler-D may download and run further software.

When Troj/Nebuler-D is installed the following file is created:

<System>\winxtx32.dll

Registry entries are created under the following in order to run code exported by winxtx32.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winxtx32

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer