Description
This is a trojan which purports to be a codec installer, to help the user view videos. The trojan instead creates a script which changes the DNS server to point to a malicious site.
Indication of Infection
- Presence of the file plugins.settings
- Websites typed in by an infected user may be redirected to malicious sites
Methods of Infection
This is a trojan detection. Unlike viruses, trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. This trojan is most commonly installed by going to a malicious site.