Sophos

Troj/Singu-S

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2006 (4.05)
Protection available since 12 July 2005 20:42:33 (GMT)
Last updated 27 March 2006 04:43:04 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Singu-S is a Trojan for the Windows platform.

Troj/Singu-S includes functionality to access the internet and communicate with a remote server via HTTP.

Troj/Singu-S copies itself to the Windows system folder as taskmone.exe and creates the file winscket.dll in the same folder.

The following registry entry is created to run taskmone.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
taskmone
<Windows system folder>\taskmone.exe

The file winscket.dll is registered as a COM object and Browser Helper Object (BHO) for Microsoft Internet Explorer, creating registry entries under:

HKCR\CLSID\{EA806E03-A6B1-205A-117C-013309406392}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA806E03-A6B1-205A-117C-013309406392}

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer