Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | May 2008 (4.29) |
| Protection available since | 26 March 2008 05:34:06 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Bizves-F is a Trojan for the Windows platform.
Troj/Bizves-F is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.
Troj/Bizves-F includes functionality to download, install and run new software.
When first run Troj/Bizves-F copies itself to <System>\cmd32.exe and may create the following files:
<Current Folder of Trojan>\asfds
<Current Folder of Trojan>\cdegfr
<Current Folder of Trojan>\fdsf
<Current Folder of Trojan>\sdfdsf
<Current Folder of Trojan>\sdfff
<Current Folder of Trojan>\wdcevf
<Current Folder of Trojan>\wdcsadsad
<Current Folder of Trojan>\zxczxc
<System>\z11.exe
<System>\z12.exe
<System>\z13.exe
<System>\z14.exe
<System>\z15.exe
<System>\z16.exe
The following registry entry is created to run cmd32.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ControlPanel
<System>\cmd32.exe internat.dll,LoadKeyboardProfile
The following registry entry is set, disabling the Windows task manager (taskmgr):
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1
