Sophos

Troj/DNSBust-A

Aliases
  • Trojan.Win32.DNSChanger.m
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2005 (3.94)
Protection available since 2 May 2005 07:53:39 (GMT)
Detected by All Sophos products

Action

More Information

Troj/DNSBust-A attempts to modify DNS settings on the computer.

The Trojan modifies the file %APPDATA%\Microsoft\Network\Connections\Pbk\rasphone.pbk by creating or changing the entries for IpDnsAddress and IpDns2Address to point to prespecified IP addresses. Troj/DNSBust-A then uses ipconfig.exe to flush the DNS cache.

Troj/DNSBust-A creates the following registry entry to run itself on system restart or logon:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DNSCacheBoost
<path to Trojan>

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer