Sophos

Troj/Delf-KA

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from March 2005 (3.91)
Protection available since 30 January 2005 15:48:35 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Delf-KA is a password stealing Trojan.

On execution the Trojan will copy itself to the Windows system folder as TAPI32INIT.EXE and also drop the file TAPI32INIT.DLL (detected as Troj/Delf-KA) into this folder.

So as to run on system startup, the Trojan will create the following registry entry:
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\ (6M8A6G00-3I18-11C0-821H-444200140P0S)\
StubPath=
C:\WINDOWS\System32\Tapi32init.exe

Troj/Delf-KA will continually monitor and reset this registry entry to make removal more difficult.

In the background the Trojan will try to steal passwords entered on the computer and submit these to a remote website.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer