Sophos

Troj/Nebuler-S

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from January 2009 (4.37)
Protection available since 22 November 2008 12:04:25 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Nebuler-S is a Trojan for the Windows platform.

Troj/Nebuler-S includes the ability to access the internet and communicate with a remote server via HTTP.

When Troj/Nebuler-S is installed the following files are created:

<Temp>\twe1.bat
<System>\winmfu32.dll

The following registry entries are created to run code exported by winmfu32.dll on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmfu32
DllName
winmfu32.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmfu32
Impersonate
0

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmfu32
Startup
JEpStartup

Registry entries are created under:

HKLM\SOFTWARE\Microsoft\MSSMGR

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer