Sophos

Troj/Bizves-F

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2008 (4.29)
Protection available since 26 March 2008 05:34:06 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Bizves-F is a Trojan for the Windows platform.
Troj/Bizves-F is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.

Troj/Bizves-F includes functionality to download, install and run new software.

When first run Troj/Bizves-F copies itself to <System>\cmd32.exe and may create the following files:

<Current Folder of Trojan>\asfds
<Current Folder of Trojan>\cdegfr
<Current Folder of Trojan>\fdsf
<Current Folder of Trojan>\sdfdsf
<Current Folder of Trojan>\sdfff
<Current Folder of Trojan>\wdcevf
<Current Folder of Trojan>\wdcsadsad
<Current Folder of Trojan>\zxczxc
<System>\z11.exe
<System>\z12.exe
<System>\z13.exe
<System>\z14.exe
<System>\z15.exe
<System>\z16.exe

The following registry entry is created to run cmd32.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ControlPanel
<System>\cmd32.exe internat.dll,LoadKeyboardProfile

The following registry entry is set, disabling the Windows task manager (taskmgr):

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer