Home Malware Programs Trojans Trojan:Win32/Delf.LN

Trojan:Win32/Delf.LN

Posted: September 12, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 98
First Seen: September 12, 2012
OS(es) Affected: Windows

Trojan:Win32/Delf.LN is a Trojan that reports and intercepts Internet traffic and may also drop potentially unwanted programs onto the affected computer. Once installed, Trojan:Win32/Delf.LN creates several files and registry entries. Trojan:Win32/Delf.LN may be distributed by other malware threats, or downloaded via drive-by downloads onto the compromised PC. While being executed, Trojan:Win32/Delf.LN strives to copy and install itself with the certain file name into the particular folder. Trojan:Win32/Delf.LN installs itself as a system driver, possibly in order to block detection and removal by modifying the specific registry subkey. Trojan:Win32/Delf.LN also modifies the certain registry entry so that it can run automatically every time you start Windows. Trojan:Win32/Delf.LN steals personal information from the vulnerable computer and send it to remote attackers.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 173.57 KB (173575 bytes)
MD5: a1bf71c38ea4ae33dce97a466eb7452f
Detection count: 72
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 13, 2012
file.exe File name: file.exe
Size: 286.72 KB (286720 bytes)
MD5: 094f9e3ed79986f1eb9f1c24d124c0bc
Detection count: 71
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: September 13, 2012
%SYSTEM%\wbem\WtiSysSt.exe File name: %SYSTEM%\wbem\WtiSysSt.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%SYSTEM%\bot_unencrypted.exe File name: %SYSTEM%\bot_unencrypted.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
WtiSysSt.exe File name: WtiSysSt.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\Services\SrvWinDrivs4" = "Description" = "(blank)""HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\Services\SrvWinDrivs4" = "DisplayName" = "SrvWinDrivs4""HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\Services\SrvWinDrivs4" = "ImagePath" = "%SYSTEM%\wbem\WtiSysSt.exe", for example "C:\WINDOWS\System32\wbem\WtiSysSt.exe" "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\Services\SrvWinDrivs4" = "Start" = "0x00000002"
Loading...