Troj/WindFind-C

Category: Viruses and Spyware
Type: Trojan
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/WindFind-C is a downloader Trojan which may download and run executables from a remote location.

The Trojan creates the folder C:\Program Files\DBS\ and copies itself to the file DSB.exe in this folder, then creates the following registry entry so that the Trojan is run automatically each time Windows is started:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
DSB = C:\Program Files\DSB\DSB.exe

Troj/WindFind-C runs continuously in the background, waiting until the user performs an internet search using one of the common search engines, such as Yahoo, Lycos, MSN Search, Google, Altavista, or Excite.

The Trojan then attempts to download an executable from a remote location to the Windows TEMP folder and execute it.

download Try Sophos products for free
Download now