Sophos

Troj/Nebuler-H

Aliases
  • BackDoor-CVT
  • TROJ_NEBULER.C
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2006 (4.11)
Protection available since 7 September 2006 12:44:41 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Nebuler-H is a Trojan for the Windows platform.

Troj/Nebuler-H gathers details relating to dialup services and sends collected information to a remote site via HTTP. The Trojan may inject code into other processes in an attempt to remain hidden.

Troj/Nebuler-H may download and run further software. Troj/Nebuler-H is a Trojan for the Windows platform.

Troj/Nebuler-H gathers details relating to dialup services and sends collected information to a remote site via HTTP. The Trojan may inject code into other processes in an attempt to remain hidden.

Troj/Nebuler-H may download and run further software.

When Troj/Nebuler-H is installed the following file is created:

<System>\winsis32.dll

The following registry entries are created to run code exported by winsis32.dll
on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winsis32
DllName
winsis32.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winsis32
Impersonate
0

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winsis32
Startup
EvtStartup

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer