Sophos

Troj/Nebuler-K

Aliases
  • Trojan.Win32.Agent.vg
  • BackDoor-CVT
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2006 (4.12)
Protection available since 15 October 2006 14:16:45 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Nebuler-K is a Trojan for the Windows platform.

Troj/Nebuler-K gathers details relating to dialup services and sends collected information to a remote site via HTTP. The Trojan may inject code into other processes in an attempt to remain hidden.

When Troj/Nebuler-K is installed the following files are created:

<System>\win<xxx>32.dll

Where <xxx> are random letters.

The following registry entries are created to run code exported by win<xxx>32.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\win<xxx>32
DllName
win<xxx>32.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\win<xxx>32
Impersonate
0

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\win<xxx>32
Startup
EvtStartup

Registry entries are created under:

HKCR\MezziaCodec.Chl\CLSID\
HKLM\SOFTWARE\Microsoft\MSSMGR\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer