Article

Gokar registry key

searchSecurity

According to a Sophos Anti-virus alert, the Gokar worm copies itself as KAREN.EXE into the infected machine's Windows directory and creates the following registry key:
HKLM\Software\MicrosoftWindows\CurrentVersion\Run\Karen = C:\karen.exe

    Requires Free Membership to View


Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.