Sophos

Troj/Dorf-BI

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2008 (4.31)
Protection available since 14 May 2008 02:25:14 (GMT)
Last updated 14 May 2008 18:52:18 (GMT)
Detected by All Sophos products

Action

More Information

When first run Troj/Dorf-BI copies itself to <Windows>\kavir.exe.

The following registry entry is created to run kavir.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
kavir
<Windows>\kavir.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer