Sophos

Troj/Delf-EYY

Aliases
  • Trojan.Win32.Delf.agq
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from January 2008 (4.25)
Protection available since 15 November 2007 20:44:58 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Delf-EYY is a Trojan for the Windows platform.

When Troj/Delf-EYY is installed the following files are created:

<Temp>\idommpkw.sys
<System>\asfsip.dll
<System>\dmint.dll
<System>\drivers\gdnvlptd.sys

The file asfsip.dll is detected as Mal/BhoDLL-A, the file and the file idommpkw.sys is detected as Troj/RootKC-Gen.

The file gdnvlptd.sys is registered as a new system driver service named "nqtzdxyu". Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\nqtzdxyu

The file asfsip.dll is registered as a COM object and Browser Helper Object (BHO) for Microsoft Internet Explorer, creating registry entries under:

HKCR\CLSID\{2B039EBB-21CD-492F-ABAE-F77D1FC9B6C6}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2B039EBB-21CD-492F-ABAE-F77D1FC9B6C6}

The following registry entry is set:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OptimalLayout
File
<System>\drivers\gdnvlptd.sys

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer