Sophos

Troj/Ermeto-A

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 28 November 2005 05:45:58 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/Ermeto-A is a Trojan for the Windows platform.

Troj/Ermeto-A monitors the user's internet access.

When Troj/Ermeto-A is installed it creates the file <System>\pKerme12.dll.

The file pKerme12.dll is registered as a COM object and ShellExecute hook, creating registry entries under:

HKCR\CLSID\(8E3526E3-F160-437B-9095-46A011877CBE)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
\ShellExecuteHooks\(8E3526E3-F160-437B-9095-46A011877CBE)

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer