Home Malware Programs Viruses Malware.Delezium

Malware.Delezium

Posted: January 6, 2010

Malware.Delezium is a malicious computer virus that opens a backdoor and allows the attacker to issue commands to control the infected PC. Deceptive viruses like Malware.Delezium often worm their way in to the system under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation. Once the server component is installed on the victim's machine, it opens a port to send a notification to the hacker. The hacker can then connect to the machine using the client component. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks. Symptoms include the presence of unknown files and registries and unexpected network traffic. Malware.Delezium poses a severe threat to your PC and should be removed immediately.

Aliases

W32/Autorun.worm.fj (McAfee)
PE_DELZIUM.A (Trend Micro)
W32/Impair-A (Sophos)
Virus:Win32/Delicium.A (Microsoft)
Win-Trojan/Agent.536744 (AhnLab)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\dotnetfx.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash\DefaultIcon][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash\shell\open\command][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DotNetRecovery]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Loading...