Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | January 2008 (4.25) |
| Protection available since | 27 November 2007 14:32:31 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Dloadr-BFS is a Trojan for the Windows platform.
Troj/Dloadr-BFS attempts to download code from the internet.
Troj/Dloadr-BFS creates the file <Windows>\system32\xpdx.sys. This file is detected as Mal/RKRustok-A.
Troj/Dloadr-BFS creates registry entries under:
HKLM\SYSTEM\CurrentControlSet\Services\xpdx\
These entries set the xpdx.sys rootkit to load as a service.
