Home Malware Programs Trojans VirTool:Win32/DelfInject.gen!AF

VirTool:Win32/DelfInject.gen!AF

Posted: June 30, 2010

VirTool:Win32/DelfInject.gen!AF is a malicious backdoor Trojan that runs in the background and allows remote access to the compromised system. VirTool:Win32/DelfInject.gen!AF attempts to propagate by exploiting local network shares. VirTool:Win32/DelfInject.gen!AF will also attempt to join a predefined IRC server and channel stolen data in order to participate in distributed denial-of-service (DDoS) attacks. The DDoS attacks will attempt to make the computer unavailable to its intended users. It is recommended that VirTool:Win32/DelfInject.gen!AF be removed immediately using a reliable anti-spyware application.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\Bifrost\Server.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Bifrost][HKEY_LOCAL_MACHINE\SOFTWARE\Bifrost][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}]
Loading...