Sophos

W32/Dorf-BD

Aliases
  • Email-Worm.Win32.Zhelatin.ww
  • W32/Nuwar@MM virus
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Email messages
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 6 April 2008 14:08:35 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Dorf-BD is a worm for the Windows platform.

When first run W32/Dorf-BD copies itself to <Windows>\aromis.exe.

The following registry entry is created to run aromis.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
aromis
<Windows>\aromis.exe

W32/Dorf-BD also creates <Windows>\aromis.config file that is used to find peers. This file can be safely deleted.

W32/Dorf-BD may arrive in email message attached with the filename withlove.exe.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer