Threat behavior
VirTool:WinNT/Citeary.B is a detection for a kernel-mode driver that hooks certain Windows API calls and is installed by
Worm:Win32/Citeary.B. Worm:Win32/Citeary.B is a worm that spreads to all available drives including the local drive and attempts to download other malware from a predefined website.
Installation
When Worm:Win32/Citeary.B is run, it drops a copy of itself as the following:
<system folder>\systeX.dll - Worm:Win32/Citeary.B
The dropped worm copy is run using the Windows utility "RUNDLL32.exe" and it then drops a device driver as the following files:
<system folder>\drivers\drver.sys - VirTool:WinNT/Citeary.B
<system drive:>\driver.sys - VirTool:WinNT/Citeary.B
The drivers are used by the worm to hook certain Windows APIs in kernel-mode.
Additional Information
Analysis by Vincent Tiu
Prevention