Sophos

Troj/Delta-I

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from December 2008 (4.36)
Protection available since 13 October 2008 08:38:11 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Delta-I is a Trojan for the Windows platform.

Troj/Delta-I runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

When Troj/Delta-I is installed the following files are created:

<Temp>\ixp000.tmp\hmkhkh~1.exe
<Windows>\ews.bat
<System>\IMG_SPA500135A.JPG.exe
<System>\hmkhkhkhk.exe

The following registry entry is created to run hmkhkhkhk.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Actualizacion
<System>\hmkhkhkhk.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer