Sophos

Troj/DNSCha-B

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from September 2008 (4.33)
Protection available since 3 July 2008 01:19:35 (GMT)
Last updated 10 July 2008 00:09:24 (GMT)
Detected by All Sophos products

Action

More Information

Troj/DNSCha-B includes functionality to modify the DNS setting, access the internet and communicate with a remote server via HTTP.

When first run Troj/DNSCha-B copies itself to <System>\<random filename>.exe.

The following registry entries are created to run Troj/DNSCha-B on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
System

Troj/DNSCha-B contains rootkit functionality.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer