Sophos

Troj/Soleno-C

Aliases
  • TR/DNSChanger.PW
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2007 (4.23)
Protection available since 29 September 2007 03:27:41 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Soleno-C is a Trojan for the Windows platform.

Troj/Soleno-C has functionality to download and execute software from a remote website. To bypass firewall restrictions Troj/Soleno-C injects code into a process such as Internet Explorer.

Troj/Soleno-C also incorporates stealthing to hide itself.

Troj/Soleno-C is a Trojan for the Windows platform.

Troj/Soleno-C has functionality to download and execute software from a remote website. To bypass firewall restrictions Troj/Soleno-C injects code into a process such as Internet Explorer.

Troj/Soleno-C also incorporates stealthing to hide itself.

When first run Troj/Soleno-C copies itself to <System>\kd<random characters>.exe.

The following registry entry is changed to run kd<random characters>.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
System
kd<random characters>.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer