Sophos

Troj/Feutel-BE

Aliases
  • Backdoor.Win32.Hupigon.ob
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 21 December 2005 23:00:43 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/Feutel-BE is a Trojan for the Windows platform.

Troj/Feutel-BE includes functionality to access the internet and communicate with a remote server via HTTP.

When first run Troj/Feutel-BE copies itself to <Windows system folder>\NLSrv.exe and creates the following files:

\Documents and Settings\LocalService\Local Settings\Temp\h.dll
\Documents and Settings\NetworkService\Local Settings\Temp\h.dll
<Temp>\h.dll
<Windows system folder>\NLSrv.DLL
<Windows system folder>\NLSrv_HOOk.DLL

The file NLSrv.exe is registered as a new system driver service named "NLSrv", with a display name of "NT LM_Security_Support_Provide" and a startup type of automatic, so that it is started automatically during system startup.

Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\NLSrv\

Troj/Feutel-BE changes settings for Microsoft Internet Explorer by modifying
values under:

HKCU\Software\Microsoft\Internet Explorer\Main\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer