Home Malware Programs Trojans Trojan:BAT/Delosc.A

Trojan:BAT/Delosc.A

Posted: January 26, 2012

Threat Metric

Ranking: 1,194
Threat Level: 2/10
Infected PCs: 242,791
First Seen: January 26, 2012
Last Seen: March 9, 2025
OS(es) Affected: Windows

Trojan:BAT/Delosc.A is a Trojan that's designed to compromise computers with Romania-specific brands of management software for legal documents. This highly specific Trojan attack was recently supported by hackers who placed Trojan:BAT/Delosc.A onto an innocent website, asistentasocialia.info, that was also focused on providing information and files for the same topic. As of the time of this writing, the website's maintainer has removed Trojan:BAT/Delosc.A's malicious files, but if you've recently downloaded files from this site or a similar site, SpywareRemove.com malware experts recommend that you run a full scan your PC to make sure that it hasn't been infected with Trojan:BAT/Delosc.A. The dropper file for Trojan:BAT/Delosc.A uses inaccurate icons that resemble those of the original documents, and will even place these files on your computer while also installing Trojan:BAT/Delosc.A. Since Trojan:BAT/Delosc.A directly targets and deletes file management programs, Trojan:BAT/Delosc.A can be considered a severe threat to any PC that makes heavy use of Romanian documentation or associated software, although the danger for computers that don't fit within this narrow target range is significantly less than the above.

Trojan:BAT/Delosc.A – a Paperwork Saboteur for Romania

Like the Stuxnet family of worms and Trojans, Trojan:BAT/Delosc.A is designed to target and destroy very specific software niches that are unlikely to be relevant for the majority of computers. Trojan:BAT/Delosc.A is hidden in the Temp folder as 'open_file.bat' and, from that well-concealed location, launches a series of deletion attempts on various folders and files. Trojan:BAT/Delosc.A's victim preferences consist of 'Aplxpert' and 'Indaco' brand programs, which are used to manage public transportation and legal documents for Romania-specific institutions. Hence, a computer that's not using any of these programs will not be significantly harmed by Trojan:BAT/Delosc.A, but any PC that is using such programs will be at risk of losing, not only access to software, but information that's contained within these programs, as well.

SpywareRemove.com malware researchers also warn that the thoroughness of Trojan:BAT/Delosc.A's attacks is aided by string-based searches that try to delete files and folders with any of the following keywords: assist, agr, alocati, aplxpert, arenda, asf, factur, gami, glob, lemne, indaco, incalz, mondo, multi, social and vmg. Trojan:BAT/Delosc.A targets drives C through H with these attacks, and drives that don't fall within this range may be immune. This generously inclusive method of searching may also cause Trojan:BAT/Delosc.A to delete unrelated programs or files that just so happen to include any of the words noted above.

How Trojan:BAT/Delosc.A Victimizes Websites to Get to You

Trojan:BAT/Delosc.A gained recent attention by being a major component in an attack against the normally hospitable website asistentasociala.info, a website that provides documentation and examples for Romanian welfare issues. Recent hacking attacks had swapped out the normal document files on this site for mislabeled .exe files that installed Trojan:BAT/Delosc.A, in addition to dropping the original document to allay suspicion. However, SpywareRemove.com malware research team is glad to report that these malicious files have since been removed by asistentasociala.info's web masters and that you don't need to worry about further Trojan:BAT/Delosc.A attacks from this source – unless, of course, the site is hacked a second time.

In light of these attacks, SpywareRemove.com malware experts recommend the utilization of an appropriate anti-malware program to scan your PC if you've downloaded files from asistentasociala.info or sites that specialize in similar topics. Caution over mislabeled links, deceptive file names and fraudulent file type categorization for icons can help you to skirt around installation attacks for Trojan:BAT/Delosc.A and similar types of PC threats, which require your manual permission to be downloaded and launched before they can harm your computer.

Technical Details

Additional Information

The following URL's were detected:
onemacusa.com
Loading...