Sophos

Troj/Deltree-X

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2008 (4.30)
Protection available since 2 May 2008 14:15:26 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Deltree-X attempts to delete the contents of the specified drive.

When run Troj/Deltree-X attempts to create the following registry entries:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SFCDisable
1

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\RunServices
<some name>
sz:deltree /y <drive>:\

Troj/Deltree-X will then try and reboot the computer.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer