Sophos

Troj/VB-HV

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/VB-HV is a backdoor Trojan that has screenshot-taking capability and other simple features. Troj/VB-HV is a backdoor Trojan that has screenshot-taking capability and other simple features.

Troj/VB-HV may set the following registry entry to run on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
SYSTEM
<path to Trojan>

Troj/VB-HV may create some of the following files:

<System>\help2.bat
<System>\help2.txt

Troj/VB-HV listens on a port for instructions from a remote user, including to take screenshots of the infected computer, to log certain window text and keystrokes, to open and close the cd tray, to run other programs, and to download and execute further files.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer