Sophos

Troj/RusDrp-H

Aliases
  • RiskTool.Win32.HideExec.f
  • Win32/Delf.NDN
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Included in our products from January 2007 (4.13)
Protection available since 13 November 2006 21:06:56 (GMT)
Detected by All Sophos products

Action

More Information

Troj/RusDrp-H is a Trojan for the Windows platform.

When Troj/RusDrp-H is installed the following files are created:

\phide_ex.log
<Windows folder>\phide_ex.sys

where the file phide_ex.sys is detected as Troj/RKRustok-G and the file phide_ex.log is a text file that may be safely deleted.

The file phide_ex.sysis registered as a new system driver service. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\phide_ex.sys\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer