Cookies are very small text files that are stored on your computer when you visit some websites. We use cookies to help provide you with the best possible online experience. By using this site, you agree that we may store and access cookies on your device. Accept this cookie or find out more.

«

»

Security Alert: Trojan.Sofacy.C

Trojan.Sofacy.C is a Trojan that steals information from the computers that it infects and downloads malicious files. It creates the following files on infected systems:

  1. %Temp%\nvsdata.dat
  2. %Temp%\nvgdata.dat
  3. %System%\netui.dll

In addition to creating these files, it also creates the following registry entries:

  • HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Explorer\ “id” = “[BINARY DATA]”
  • HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ Explorer\”id” = “[BINARY DATA]”
  • HKEY_CLASSES_ROOT\CLSID\ {61113868-6B5D-4195-8966-B26462B909FA}\ InProcServer32\ “[DEFAULT]” = “%System%\ netui.dll”
  • HKEY_LOCAL_MACHINE\ SOFTWARE\Microsoft\ Windows\ CurrentVersion\ Explorer\ SharedTaskScheduler\ “{61113868-6B5D-4195-8966-B26462B909FA}” = “Network User Interface”

Finding these files and these registry settings is an indication that you are infected with this Trojan. Before removing the infection, backup your registry following the steps here.

Then, remove the infection as follows:

  1. Press [Windows Key] + [R], type REGEDIT and click OK.
  2. Navigate to the registry key: HKEY_CURRENT_USER\ Software\ Microsoft\ Windows\ CurrentVersion\ Explorerr
  3. Delete the registry entry: “id” = “[BINARY DATA]”
  4. Navigate to the registry key: HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ Explorer
  5. Delete the registry entry: “id” = “[BINARY DATA]”
  6. Navigate to the registry key: HKEY_CLASSES_ROOT\CLSID\ {61113868-6B5D-4195-8966-B26462B909FA}\ InProcServer32
  7. Delete the registry entry: “[DEFAULT]” = “%System%\ netui.dll”
  8. Navigate to the registry key: HKEY_LOCAL_MACHINE\ SOFTWARE\ Microsoft\ Windows\ CurrentVersion\ Explorer\ SharedTaskScheduler
  9. Delete the registry entry: “{61113868-6B5D-4195-8966-B26462B909FA}” = “Network User Interface”
  10. Close the Registry Editor and re-boot your PC.