Summary

Summary
More Information
| Affected operating systems | Windows |
|---|---|
| Protection available since | 6 February 2008 09:17:26 (GMT) |
| Last updated | 12 February 2008 19:46:18 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
More Information

Summary
More Information
Troj/Nuclear-BE is a backdoor Trojan for the Windows platform that provides an unauthorized remote access to the infected computer.
When first run Troj/Nuclear-BE copies itself to <WINDOWS>\NR\example.exe
Troj/Nuclear-BE attempts to drop a file which is also dectected as Troj/Nuclear-BE. The dropped file has the capability to take system snapshots, log keyboard and can give access to a remote server.
Registry entries are created under:
HKCR\dllfile\shell\open\command
When first run Troj/Nuclear-BE copies itself to <WINDOWS>\NR\example.exe
Troj/Nuclear-BE attempts to drop a file which is also dectected as Troj/Nuclear-BE. The dropped file has the capability to take system snapshots, log keyboard and can give access to a remote server.
Registry entries are created under:
HKCR\dllfile\shell\open\command
rundll32.exe
HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}
Troj/Nuclear-BE copies itself as
<WINDOWS>\NR\example.exe

