Sophos

Troj/Delf-KM

Aliases
  • Trojan-Clicker.Win32.Delf.bk
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from May 2005 (3.93)
Protection available since 5 April 2005 21:57:45 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Delf-KM is a Trojan for Windows based systems. The Trojan periodically opens a pre-specified webpage.

The Trojan copies itself to the Windows directory as yahoo.exe. To ensure that it is run on system start it creates the following registry entries:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Winhost
C:\WINDOWS\yahoo.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Winhost1
C:\WINDOWS\yahoo.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Winhost2
C:\WINDOWS\yahoo.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Winhost3
C:\WINDOWS\yahoo.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Winhost4
C:\WINDOWS\yahoo.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer