Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Included in our products from | June 2008 (4.30) |
| Protection available since | 23 April 2008 04:01:13 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
W32/Sohana-AT is a Trojan for the Windows platform.
W32/Sohana-AT includes functionality to download, install and run new software.
When W32/Sohana-AT is installed it creates the file <Windows>\taskmng.exe.
The following registry entries are set, disabling system software:
HKCU\Software\Microsoft\Win dows\CurrentVersion\Policies\System
DisableTaskMgr
1
HKCU\Software\Microsoft\Win dows\CurrentVersion\Policies\System
DisableRegistryTools
1
The following registry entry is set:
HKLM\SOFTWARE\Microsoft\Wi ndows\CurrentVersion\Run
Task Manager
<Windows>\taskmng.exe
Registry entries are created under:
HKCU\Software\Microsoft\Int ernet Explorer\Main
HKCU\Software\Policies\Micr osoft\Internet Explorer\Control Panel
HKCU\Software\Yahoo\pager\V iew\YMSGR_Launchcast
HKCU\Software\Yahoo\pager\V iew\YMSGR_buzz
