Sophos

Troj/Delf-SY

Aliases
  • Backdoor.Win32.Delf.sy
  • PWS-Banker.gen.b
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from October 2005 (3.98)
Protection available since 16 August 2005 15:26:12 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Delf-SY is a Keylogging Trojan for the Windows platform.

Troj/Delf-SY contains functionality to communicate with a remote host via FTP.

When first run Troj/Delf-SY copies itself to <System>\wf.exe and creates the file <System>\keylog.dll.

The file keylog.dll is detected as Troj/Delf-SY.

The following registry entry is created to run wf.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WinFire
<System>\WF.exe

Registry entries are created under:

HKLM\SOFTWARE\WinFire\

Troj/Delf-SY is known to be dropped by Troj/Mdrop-Y.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer