Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | May 2005 (3.93) |
| Protection available since | 5 April 2005 21:57:45 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Delf-KM is a Trojan for Windows based systems. The Trojan periodically opens a pre-specified webpage.
The Trojan copies itself to the Windows directory as yahoo.exe. To ensure that it is run on system start it creates the following registry entries:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Winhost
C:\WINDOWS\yahoo.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Winhost1
C:\WINDOWS\yahoo.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Winhost2
C:\WINDOWS\yahoo.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Winhost3
C:\WINDOWS\yahoo.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Winhost4
C:\WINDOWS\yahoo.exe
