Home Malware Programs Trojans Trojan-Downloader.Win32.Delf.cgx

Trojan-Downloader.Win32.Delf.cgx

Posted: April 6, 2010

Trojan-Downloader.Win32.Delf.cgx is a Trojan installed stealthily to download malware onto a targeted computer. Trojan-Downloader.Win32.Delf.cgx uses multiple servers on the Internet to do its dirty work. Trojan-Downloader.Win32.Delf.cgx's symptoms include corrupt network connections, self-mutation, disabling of security software and the installation of harmful malware. Trojan-Downloader.Win32.Delf.cgx may also transmit personal information without your consent. Remove this parasite immediately using a reliable malware remover.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %UserProfile%\Local Settings\Application Data\\
    2 %UserProfile%\Local Settings\Application Data\\
    3 tssd.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = "no"HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyEnable" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyOverride" = "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "ProxyServer" = "http=127.0.0.1:5555"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" = ".exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = "1"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""HKEY_CURRENT_USER\Software\avsuiteHKEY_LOCAL_MACHINE\SOFTWARE\avsuiteHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ""
Loading...