Home Malware Programs Viruses Virus.Win32.DelfInject

Virus.Win32.DelfInject

Posted: August 8, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 157
First Seen: August 8, 2012
Last Seen: April 16, 2023
OS(es) Affected: Windows

Virus.Win32.DelfInject is a semi-generic name for a Trojan that injects its code into system processes to accomplish its functions, which usually involve installing other PC threats. This makes detecting or deleting Virus.Win32.DelfInject difficult without specialized anti-malware software, since, as far as your memory processes are concerned, Virus.Win32.DelfInject appears to be a normal part of your operating system. SpywareRemove.com malware experts also recommend that you keep anti-malware software to defeat Virus.Win32.DelfInject due to Virus.Win32.DelfInject's habit of detecting this software and performing its own deletion (presumably to prevent Virus.Win32.DelfInject from being analyzed) in cases of positive detections. Neither Virus.Win32.DelfInject nor its payload have any form of confirmed symptoms for their attacks, beyond the minimal extra memory usage that Virus.Win32.DelfInject requires for its functions.

Virus.Win32.DelfInject: a Fine Houdini Act for Malicious Software

Although some sources classify Virus.Win32.DelfInject as a virus, SpywareRemove.com malware researchers consider Virus.Win32.DelfInject more properly to be defined as a Trojan downloader or rootkit, since Virus.Win32.DelfInject hasn't been found to distribute itself, like a virus, by infecting many types of files indiscriminately. Instead, Virus.Win32.DelfInject's infection process is distinct and limited to compromising 'rundll32.exe,' which Virus.Win32.DelfInject then uses to delete its original EXE file. Thereafter, Virus.Win32.DelfInject launches itself in memory as part of the svchost.exe process and is indiscernible from the rest of your OS, except for any minor changes in resource usage that you may be able to see.

Virus.Win32.DelfInject's main function is to make contact with remote servers for the purpose of downloading other files, potentially including other Trojans, spyware, configuration data or updates for its own behavior. SpywareRemove.com malware research team, therefore, recommends extremely thorough scans of any hard drive that's infected by Virus.Win32.DelfInject, since Virus.Win32.DelfInject can install other PC threats at its own whim. Common payloads for Virus.Win32.DelfInject and similar Trojan downloaders often include banking Trojans that steal bank account data or PC threats that attack your computer's security software.

Why Virus.Win32.DelfInject's Paranoia Can Be to Your Benefit

At this time, Virus.Win32.DelfInject's confirmed aliases include Trojan.DownLoader5.12990, Win32/Delf.ODS Trojan, VirTool:Win32/DelfInject, Trojan.DR.Injector!8ocyJC5SGmA and Trojan-Dropper.Win32.Injector.uzb. Although Virus.Win32.DelfInject is several years old, its attacks remain functional for most versions of Windows, and SpywareRemove.com malware experts recommend that you take all due precautionary measures against potential Virus.Win32.DelfInject infection routes and attacks.

One interesting trait of Virus.Win32.DelfInject is that Virus.Win32.DelfInject attempts to detect prominent brands of anti-malware software on your PC. While this function isn't unusual ( SpywareRemove.com malware analysts have also seen it, for example, in rogue anti-malware scanners from the FakeVimes family), Virus.Win32.DelfInject's response to a positive detection is a little abnormal - Virus.Win32.DelfInject will terminate itself automatically to avoid detection or deletion. While this neuters Virus.Win32.DelfInject's ability for harm in the short term, you should still remove Virus.Win32.DelfInject later with anti-malware scans as is convenient.

Aliases

Generic Trojan [Panda]PSW.Banker6.ACQZ [AVG]W32/Sasfis.CZB!tr [Fortinet]Virus.Win32.DelfInject [Ikarus]Trojan/Win32.Gen [AhnLab-V3]TR/Graftor.30277.24 [AntiVir]UnclassifiedMalware [Comodo]Mal/Behav-053 [Sophos]HEUR:Trojan.Win32.Generic [Kaspersky]Win32:Crypt-NIO [Trj] [Avast]Trojan.Gen.2 [Symantec]Riskware [K7AntiVirus]PWS-Banker!h2s [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\QarrqsT\WpqlunT\RklboxQ.exe File name: RklboxQ.exe
Size: 244.73 KB (244736 bytes)
MD5: d758760aef803d058794400d4eb0d2c9
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\QarrqsT\WpqlunT
Group: Malware file
Last Updated: May 13, 2013

Additional Information

The following URL's were detected:
generalsearches.com
Loading...