Home Malware Programs Browser Hijackers Trojan-Downloader.Win32.Delf.ks

Trojan-Downloader.Win32.Delf.ks

Posted: May 24, 2006

Trojan-Downloader.Win32.Delf.ks may be found in the System32 folder on 9X machines. Trojan-Downloader.Win32.Delf.ks copies its file(s) to your harddisk. Then it creates new startup key with name Start Page and value svcnt32.exe.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 biasfardihuy.dll
    2 birdasfihuy32.dll
    3 psg.exe
    4 rbs.exe
    5 rzs.exe
    6 sec.exe
    7 shdocvn.dll
    8 svcnt32.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}00000535-0000-0010-8000-00aa006d2ea4compatibilityflags786c369d-409a-456f-a13c971eada850c6compatibilityflagsHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runstartpage
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}13709620-c279-11ce-a49e-444553540000
Loading...