Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | December 2006 (4.12) |
| Protection available since | 7 September 2006 20:16:13 (GMT) |
| Last updated | 6 November 2006 06:17:21 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Nebuler-I is a Trojan for the Windows platform.
Troj/Nebuler-I gathers details relating to dialup services and sends collected information to a remote site via HTTP. The Trojan may inject code into other processes in an attempt to remain hidden.
When Troj/Nebuler-I is installed the following files are created:
<Temp>\mst1.bat
<current folder>\mit.bat
<System>\win<XXX>32.dll
where <XXX> are random letters.
The win<XXX>32.dll file is also detected as Troj/Nebuler-I, mst1.bat is a copy of the win<XXX>32.dll file and mit.bat is not malicious file that will delete the Trojan main excutable once a dll component is installed.
The following registry entries are created to run code exported by win<XXX>32.dll on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\win<XXX>32
DllName
win<XXX>32.dll
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\win<XXX>32
Impersonate
0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\win<XXX>32
Startup
EvtStartup
