Sophos

Troj/Nuclear-BE

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from April 2008 (4.28)
Protection available since 6 February 2008 09:17:26 (GMT)
Last updated 12 February 2008 19:46:18 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Nuclear-BE is a backdoor Trojan for the Windows platform that provides an unauthorized remote access to the infected computer.

When first run Troj/Nuclear-BE copies itself to <WINDOWS>\NR\example.exe

Troj/Nuclear-BE attempts to drop a file which is also dectected as Troj/Nuclear-BE. The dropped file has the capability to take system snapshots, log keyboard and can give access to a remote server.

Registry entries are created under:

HKCR\dllfile\shell\open\command

Troj/Nuclear-BE is a backdoor Trojan for the Windows platform that provides an unauthorized remote access to the infected computer.

When first run Troj/Nuclear-BE copies itself to <WINDOWS>\NR\example.exe

Troj/Nuclear-BE attempts to drop a file which is also dectected as Troj/Nuclear-BE. The dropped file has the capability to take system snapshots, log keyboard and can give access to a remote server.

Registry entries are created under:

HKCR\dllfile\shell\open\command
rundll32.exe

HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}

Troj/Nuclear-BE copies itself as

<WINDOWS>\NR\example.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer