Sophos

Sophos blogs

Troj/Delf-KA

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 30 January 2005 15:48:35 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Delf-KA is a password stealing Trojan.

On execution the Trojan will copy itself to the Windows system folder as TAPI32INIT.EXE and also drop the file TAPI32INIT.DLL (detected as Troj/Delf-KA) into this folder.

So as to run on system startup, the Trojan will create the following registry entry:
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\ (6M8A6G00-3I18-11C0-821H-444200140P0S)\
StubPath=
C:\WINDOWS\System32\Tapi32init.exe

Troj/Delf-KA will continually monitor and reset this registry entry to make removal more difficult.

In the background the Trojan will try to steal passwords entered on the computer and submit these to a remote website.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer