Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | January 2008 (4.25) |
| Protection available since | 15 November 2007 20:44:58 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Delf-EYY is a Trojan for the Windows platform.
When Troj/Delf-EYY is installed the following files are created:
<Temp>\idommpkw.sys
<System>\asfsip.dll
<System>\dmint.dll
<System>\drivers\gdnvlptd.sys
The file asfsip.dll is detected as Mal/BhoDLL-A, the file and the file idommpkw.sys is detected as Troj/RootKC-Gen.
The file gdnvlptd.sys is registered as a new system driver service named "nqtzdxyu". Registry entries are created under:
HKLM\SYSTEM\CurrentControlSet\Services\nqtzdxyu
The file asfsip.dll is registered as a COM object and Browser Helper Object (BHO) for Microsoft Internet Explorer, creating registry entries under:
HKCR\CLSID\{2B039EBB-21CD-492F-ABAE-F77D1FC9B6C6}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2B039EBB-21CD-492F-ABAE-F77D1FC9B6C6}
The following registry entry is set:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OptimalLayout
File
<System>\drivers\gdnvlptd.sys
