Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | December 2006 (4.12) |
| Protection available since | 15 October 2006 14:16:45 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Nebuler-K is a Trojan for the Windows platform.
Troj/Nebuler-K gathers details relating to dialup services and sends collected information to a remote site via HTTP. The Trojan may inject code into other processes in an attempt to remain hidden.
When Troj/Nebuler-K is installed the following files are created:
<System>\win<xxx>32.dll
Where <xxx> are random letters.
The following registry entries are created to run code exported by win<xxx>32.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\win<xxx>32
DllName
win<xxx>32.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\win<xxx>32
Impersonate
0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\win<xxx>32
Startup
EvtStartup
Registry entries are created under:
HKCR\MezziaCodec.Chl\CLSID\
HKLM\SOFTWARE\Microsoft\MSSMGR\
