Home Malware Programs Trojans Souljet

Souljet

Posted: March 28, 2006

Souljet, also known as Paltus, is a trojan designed to retrieve computer details and steal user sensitive information. The spyware logs all user keystrokes, collects passwords, login names and other confidential information and transfers it to a predetermined remote host. Souljet is able to hide its presence by injecting malicious code into legitimate processes. The trojan automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 soul.dll
    2 spoo1sv.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunspoo1sv
Loading...