Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 16 August 2005 20:13:03 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Winflux-C is a backdoor Trojan for the Windows platform.
Troj/Winflux-C gives a remote intruder control of the infected computer.
When first run Troj/Winflux-C copies itself to <System>\loadfax.exe.
The following registry entries are created to run loadfax.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\RUNONCE
*loadfax
<System>\loadfax.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
*loadfax
<System>\loadfax.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
loadfax
<System>\loadfax.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
loadfax
<System>\loadfax.exe
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\(10B3BB21-1D4E-8B4D-5A5B-4A670C3D225C)
StubPath
<System>\loadfax.exe 2
Troj/Winflux-C may inject its code into a running process in order to hide from the user.
Troj/Winflux-C has been seen dropped by Troj/Fakezo-A.
