Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | November 2007 (4.23) |
| Protection available since | 29 September 2007 03:27:41 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Soleno-C is a Trojan for the Windows platform.
Troj/Soleno-C has functionality to download and execute software from a remote website. To bypass firewall restrictions Troj/Soleno-C injects code into a process such as Internet Explorer.
Troj/Soleno-C also incorporates stealthing to hide itself.
Troj/Soleno-C has functionality to download and execute software from a remote website. To bypass firewall restrictions Troj/Soleno-C injects code into a process such as Internet Explorer.
Troj/Soleno-C also incorporates stealthing to hide itself.
When first run Troj/Soleno-C copies itself to <System>\kd<random characters>.exe.
The following registry entry is changed to run kd<random characters>.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
System
kd<random characters>.exe
