Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/VB-HV is a backdoor Trojan that has screenshot-taking capability and other simple features. Troj/VB-HV is a backdoor Trojan that has screenshot-taking capability and other simple features.
Troj/VB-HV may set the following registry entry to run on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
SYSTEM
<path to Trojan>
Troj/VB-HV may create some of the following files:
<System>\help2.bat
<System>\help2.txt
Troj/VB-HV listens on a port for instructions from a remote user, including to take screenshots of the infected computer, to log certain window text and keystrokes, to open and close the cd tray, to run other programs, and to download and execute further files.
