Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | June 2005 (3.94) |
| Protection available since | 2 May 2005 07:53:39 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/DNSBust-A attempts to modify DNS settings on the computer.
The Trojan modifies the file %APPDATA%\Microsoft\Network\Connections\Pbk\rasphone.pbk by creating or changing the entries for IpDnsAddress and IpDns2Address to point to prespecified IP addresses. Troj/DNSBust-A then uses ipconfig.exe to flush the DNS cache.
Troj/DNSBust-A creates the following registry entry to run itself on system restart or logon:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DNSCacheBoost
<path to Trojan>
