|
|
|
VIRUS NAME
: Backdoor.Tela
Trojan
Characteristics
This Trojan
is identified as "Generic Backdoor" using the specified DAT.
This is a remote access Trojan, written in Delphi. If it is run on a host system,
it will attempt to connect to the Internet, and open TCP port 6712 and 6713,
listening for instructions from a client component. It will also modify the
registry to load at Windows startup.
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run\Sttray32 = %Windir%\STTRAY32.EXE
This Trojan may attempt to connect to an ftp server on the Geocities domain.
This Trojan may appear to be an installation program based on its file icon:
This Trojan contains the string "TELA".
Symptoms
Open TCP ports 6712 and
6713.
Firewall alerts of attempts
to access the Internet by "STTRAY32.EXE".
Method
Of Infection
If this trojan is run on the local system, it will configure itself to load
each time Windows is started.
|
|
|