Home Malware Programs Trojans Win32/Delf.QCZ

Win32/Delf.QCZ

Posted: August 31, 2011

Win32/Delf.QCZ (also known as Trojan.Badlib or Trojan.Win32.Miner.h) is a computer infection that sets the affected PC user's privacy at risk. Win32/Delf.QCZ can also affect a compromised computer and its integrity. Win32/Delf.QCZ uses a HTTP protocol as a channel of communication and installs its own executables that are its components. When Win32/Delf.QCZ is installed on the infected PC system, some of its malicious components download and install the Bitcoin software and also provide tasks to be performed. Win32/Delf.QCZ is also able to check if the PC is equipped with an ATI graphics card and will download the drivers if needed. This may lead to computer lags and some suspicious processes running on Process Explorer. Find a legitimate and effective security application to detect and remove Win32/Delf.QCZ as quickly as possible.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\RANDOM CHARACTERS.exe"HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating
Loading...