Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 19 April 2005 21:17:15 (GMT) |
| Last updated | 16 May 2005 20:06:49 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Vbbot-B is a backdoor Trojan.
Troj/Vbbot-B contains functionality to act as a proxy server and to download and run files.
Troj/Vbbot-B will create a file named IDXOCB.DLL. This is a text file that contains logging information.
In order to run automatically each time a user logs in, Troj/Vbbot-B will set the following registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
tcp checker
tcpcheck.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
tcp checker
tcpcheck.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
tcp checker
tcpcheck.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
tcp checker
tcpcheck.exe
Troj/Vbbot-B will also run as a service named "EthernetService" with a display name of "Ethernet Service"
Registry entries will be created under the following branch:
HKLM\System\CurrentControlSet\Services\EthernetService
In particular, the following registry entry is created:
HKLM\System\CurrentControlSet\Services\EthernetService
ImagePath
ethernet.exe
