Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | June 2006 (4.06) |
| Protection available since | 7 May 2006 13:20:52 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Slogger-K is a Trojan for the Windows platform.
Troj/Slogger-K includes the following functionalities to:
- communicate with remote servers via HTTP
- download and run files
- terminate anti-virus and security related processes
- send email
Troj/Slogger-K is a Trojan for the Windows platform.
Troj/Slogger-K includes the following functionalities to:
- communicate with remote servers via HTTP
- download and run files
- terminate anti-virus and security related processes
- send email
When first run Troj/Slogger-K copies itself to <System>\<random filename>.exe
and creates the file <System>\<random filename>.dll.
The following registry entry is created to run code exported by the Trojan
library on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
SysTray.Exbt
(5368D5FC-6F6C-4f5b-B564-E67214F67552)
The DLL file is registered as a COM object, creating registry entries under:
HKCR\CLSID\(5368D5FC-6F6C-4f5b-B564-E67214F67552)
Troj/Slogger-K changes settings for Microsoft Internet Explorer by modifying
values under:
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\
