Sophos

Troj/Feutel-DB

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from August 2006 (4.08)
Protection available since 25 May 2006 22:27:50 (GMT)
Last updated 26 June 2006 21:10:03 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Feutel-DB is a backdoor Trojan for the Windows platform.

When first run Troj/Feutel-DB copies itself to <Windows folder>\Explore.exe and creates the following files:

<Windows system folder>\god.sys
<Windows system folder>\ranx.dll

The files god.sys and ranx.dll are detected as Troj/Hackvan-A.

The file Explore.exe is registered as a new system driver service named "Network DDE Connections", with a display name of "Network DDE Connections" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\Network DDE Connections\

The file god.sys is registered as a new system driver service named "VANTI", with a display name of "VANTI" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\VANTI\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer