Sophos

Troj/Nebuler-I

Aliases
  • Trojan-Downloader.Win32.Small.bwy
  • BackDoor-CVT
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2006 (4.12)
Protection available since 7 September 2006 20:16:13 (GMT)
Last updated 6 November 2006 06:17:21 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Nebuler-I is a Trojan for the Windows platform.

Troj/Nebuler-I gathers details relating to dialup services and sends collected information to a remote site via HTTP. The Trojan may inject code into other processes in an attempt to remain hidden.

When Troj/Nebuler-I is installed the following files are created:

<Temp>\mst1.bat
<current folder>\mit.bat
<System>\win<XXX>32.dll

where <XXX> are random letters.

The win<XXX>32.dll file is also detected as Troj/Nebuler-I, mst1.bat is a copy of the win<XXX>32.dll file and mit.bat is not malicious file that will delete the Trojan main excutable once a dll component is installed.

The following registry entries are created to run code exported by win<XXX>32.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\win<XXX>32
DllName
win<XXX>32.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\win<XXX>32
Impersonate
0

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\win<XXX>32
Startup
EvtStartup

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer