|
Alert ID : FrSIRT/ALRT-2008-02841
Aliases : N/A
Size : N/A
Rated as : Low Risk  Release Date : 2008-05-14
Description
When first run Troj/Dorf-BI copies itself to <Windows>\kavir.exe. The following registry entry is created to run kavir.exe on startup: HKCU\Software\Microsoft\Windows\CurrentVersion\Run kavir <Windows>\kavir.exe.
References
http://www.sophos.com/security/analyses/viruses-and-spyware/trojdorfbi.html
Credits
Reported by Sophos
ChangeLog
2008-05-14 - Initial Release
Disclaimer
The information contained herein was obtained from third party sources and is solely based upon the data available at the time of publication. | |
|