Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Included in our products from | April 2008 (4.28) |
| Protection available since | 6 February 2008 09:17:26 (GMT) |
| Last updated | 12 February 2008 19:46:18 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Nuclear-BE is a backdoor Trojan for the Windows platform that provides an unauthorized remote access to the infected computer.
When first run Troj/Nuclear-BE copies itself to <WINDOWS>\NR\example.exe
Troj/Nuclear-BE attempts to drop a file which is also dectected as Troj/Nuclear-BE. The dropped file has the capability to take system snapshots, log keyboard and can give access to a remote server.
Registry entries are created under:
HKCR\dllfile\shell\open\command
When first run Troj/Nuclear-BE copies itself to <WINDOWS>\NR\example.exe
Troj/Nuclear-BE attempts to drop a file which is also dectected as Troj/Nuclear-BE. The dropped file has the capability to take system snapshots, log keyboard and can give access to a remote server.
Registry entries are created under:
HKCR\dllfile\shell\open\command
rundll32.exe
HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}
Troj/Nuclear-BE copies itself as
<WINDOWS>\NR\example.exe
