Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | May 2005 (3.93) |
| Protection available since | 31 March 2005 13:15:17 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Dloader-KF is a downloader Trojan for the Windows platform.
Troj/Dloader-KF will copy itself to the Windows system folder as IExplorer.exe and faxcomdos.exe. The Trojan will also drop two harmless files, <Windows folder>\msfport.dll and <Windows system folder>\wincontxt.dll.
Troj/Dloader-KF will then contact a predefined URL to download and execute files.
Troj/Dloader-KF will create the following registry entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
11
"<Windows system folder>\faxcomdos.exe"
