Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 7 December 2005 11:27:24 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Slogger-F is a backdoor Trojan for the Windows platform.
When first run, Troj/Slogger-F copies itself to
s the file <System>/<random>.dll.
Troj/Slogger-F includes functionality to:
- communicate with remote servers via HTTP
- send email
The following registry entry is created to run code exported by the Trojan library on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\
ShellServiceObjectDelayLoad
SysTray.Exiv
(2963ECFC-4E5C-2f3b-B334-D67434FC72E0)
The file <random>.dll is registered as a COM object, creating registry entries under:
HKCR\CLSID\(2963ECFC-4E5C-2f3b-B334-D67434FC72E0)
Troj/Slogger-F changes settings for Microsoft Internet Explorer by modifying values under:
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\
