Sophos

Troj/Dloader-EK

Aliases
  • TrojanDownloader.Win32.Delf.EK
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from November 2004 (3.87)
Protection available since 4 October 2004 13:20:39 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Dloader-EK is a downloading Trojan.

The Trojan attempts to download several files, each from up to three preconfigured URLs, to the Windows system folder. If no files could be downloaded, the Trojan will try again later.

Once the files have been downloaded, they are executed.

In order to ensure that it is run at system startup, the Trojan creates the following registry entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
cmrss = "C:\Windows\System32\crmss.exe"

Troj/Dloader-EK also copies itself to the Windows system folder.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer