Selected viruses, spyware, and other threats: sorted alphabetically
Win32/Spy.Delf.OKH
|
Short description
Win32/Spy.Delf.OKH is a trojan that steals sensitive information. The trojan can send the information to a remote machine.Installation
When executed, the trojan creates the following files:- C:WINDOWSsystem32prikas.bat
- C:WINDOWSsystem32heslo.bat
- C:WINDOWSsystem32formatd.bat
- C:WINDOWSsystem32format.bat
- C:WINDOWSsystem32pistoj
- nazov.txt
The file is stored in the following location:
- C:WINDOWSsystem32pistojfrajerka.exe
- [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersion
Run]
"frajerka" = "C:WINDOWSsystem32pistojfrajerka.exe"
Other information
The trojan connects to the following addresses:- http://www.hackeri.tym.sk
The files are saved into the following folder:
- C:WINDOWSsystem32pistoj
- formatd.txt
- format.txt
- spusti.txt
- frajerka.exe
- [HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersion
Run]
"heslo" = "C:WINDOWSsystem32heslo.bat"
"ImagePath" = "%homedrive%WINDOWSsystem_32.bat"
"formatd" = "C:WINDOWSsystem32formatd.bat"
"format" = "C:WINDOWSsystem32format.bat"
- %homedrive%WINDOWSy.reg
- %homedrive%WINDOWSsystem_32.bat
- D:
- %homedrive%
- mojkar
- computer name
