Sophos

Troj/Dorf-K

Aliases
  • Trojan-Downloader.Win32.Tibs.ll
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from August 2007 (4.20)
Protection available since 26 June 2007 02:47:35 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dorf-K is a Trojan for the Windows platform.

When Troj/Dorf-K is installed it creates the file <System>\windev-<4 random characters>-<4 random characters >.sys, detected as Mal/EncPk-K.

This dropped file is registered as a new system driver service with the same service and display name as the file, and a startup type of automatic so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\windev-<4 random characters>-<4 random characters>

Troj/Dorf-K may attempts to download and execute files from a remote location

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer