Hello,
People on this forum said it's clean from any malicious code (NOD32 says different). It works, but I don't have any clue, why it copy some bullcrap into Windows/System32/winupdate (This folder shouldn't be here). It creates "svchost s" (no extension) in it and creates some reg keys too.
NOD32 and Ad-Aware says it's Trojan.Bifrose.NYC and NOD32 threatlog shows "svchost s - attempt to run itself on system startup". 100% sure it's from KLOAD.exe - just tried (everything is ok, but when I ran kload, winupdate folder is created etc.). Anyone have a clean one/same problems?
Thank you for your constructive posts






