Sophos

Troj/DNSBust-A

Aliases
  • Trojan.Win32.DNSChanger.m
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 2 May 2005 07:53:39 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/DNSBust-A attempts to modify DNS settings on the computer.

The Trojan modifies the file %APPDATA%\Microsoft\Network\Connections\Pbk\rasphone.pbk by creating or changing the entries for IpDnsAddress and IpDns2Address to point to prespecified IP addresses. Troj/DNSBust-A then uses ipconfig.exe to flush the DNS cache.

Troj/DNSBust-A creates the following registry entry to run itself on system restart or logon:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DNSCacheBoost
<path to Trojan>

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer