Discovered: February 5, 2001
Updated: February 13, 2007 11:53:45 AM
Type: Trojan Horse
This is a variant of the well-known backdoor Trojan,
Netbus. This variant contains a registry file that modifies the Windows registry. This was done because NetBus Pro version 2.1 has been redesigned so that, by default, it is not hidden. This allows NetBus Pro version 2.1 to be used as a legitimate remote-control tool. When this variant is run, it modifies the Windows registry so that NetBus runs in stealth mode.
NOTE: Netbus Pro version 2.1 is not, in and of itself, a viral program. Norton AntiVirus therefore, does not detect the Netbus executable, but only the "package" that contains both the Backdoor.Netbus.444051registry file and the Netbus executable.
Protection
-
Initial Rapid Release version February 6, 2001
-
Latest Rapid Release version February 6, 2001
-
Initial Daily Certified version February 6, 2001
-
Latest Daily Certified version January 15, 2008 revision 017
-
Initial Weekly Certified release date pending
Click for a more detailed description of Rapid Release and Daily Certified virus definitions.
Threat Assessment
Wild
-
Wild Level: Low
-
Number of Infections: 0 - 49
-
Number of Sites: 0 - 2
-
Geographical Distribution: Low
-
Threat Containment: Easy
-
Removal: Moderate
Damage
Distribution
Writeup By: Neal Hindocha