Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | August 2006 (4.08) |
| Protection available since | 25 May 2006 22:27:50 (GMT) |
| Last updated | 26 June 2006 21:10:03 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Feutel-DB is a backdoor Trojan for the Windows platform.
When first run Troj/Feutel-DB copies itself to <Windows folder>\Explore.exe and creates the following files:
<Windows system folder>\god.sys
<Windows system folder>\ranx.dll
The files god.sys and ranx.dll are detected as Troj/Hackvan-A.
The file Explore.exe is registered as a new system driver service named "Network DDE Connections", with a display name of "Network DDE Connections" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\Network DDE Connections\
The file god.sys is registered as a new system driver service named "VANTI", with a display name of "VANTI" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\VANTI\
