Home Malware Programs Trojans Nethell

Nethell

Posted: March 28, 2006

Nethell is a trojan, which secretly downloads spywares from the Internet and installs them to the compromised computer. It also attempts to intercept network traffic in order to steal user sensitive information such as many login names and passwords. The trojan may block access to some legitiamte web sites and send the user to malicious Internet resources.

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOTNetHelper.HookHKEY_CLASSES_ROOTNetHelper.Hook.1
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}0324D9F1-2199-4424-98C7-A0E8CC45743B54DCBD5A-3FDC-490F-B9AE-5B9DBAA39BEC1593C741-C011-46FE-99FC-3805C28328BA
Loading...