Threat Database Trojans Trojan:Win32/Delf.LN

Trojan:Win32/Delf.LN

By Sumo3000 in Trojans

Trojan:Win32/Delf.LN is a Trojan that reports and intercepts HTTPS and HTTP Internet traffic (safe and unsafe Internet data) so as to gain your personal information involving user names, passwords, cookies and website session histories. Trojan:Win32/Delf.LN may also distribute potentially harmful software onto the infected PC. While being installed, Trojan:Win32/Delf.LN creates system files and registry entries. Trojan:Win32/Delf.LN may be spread by other malware infections, or downloaded via drive-by downloads onto the affected computer. Trojan:Win32/Delf.LN transfers the collected information to a remote server. Trojan:Win32/Delf.LN may contact a remote servers for downloading arbitrary files. Trojan:Win32/Delf.LN can also work as a proxy, possibly to enable a cybercriminal to use your network connection. Trojan:Win32/Delf.LN can fool websites into thinking you are using a different web browser or program in order to block detection and removal.

SpyHunter Detects & Remove Trojan:Win32/Delf.LN

File System Details

Trojan:Win32/Delf.LN may create the following file(s):
# File Name MD5 Detections
1. %SYSTEM%\wbem\WtiSysSt.exe
2. "WtiSysSt.exe"
3. "bot_unencrypted.exe"
4. file.exe 094f9e3ed79986f1eb9f1c24d124c0bc 0
5. file.exe a1bf71c38ea4ae33dce97a466eb7452f 0

Registry Details

Trojan:Win32/Delf.LN may create the following registry entry or registry entries:
"HKLM\SYSTEM\ControlSet\Services\SrvWinDrivs4" = "ImagePath" = "%SYSTEM%\wbem\WtiSysSt.exe", for example
"HKLM\SYSTEM\ControlSet\Services\SrvWinDrivs4" = "DisplayName" = "SrvWinDrivs4"
"HKLM\SYSTEM\ControlSet\Services\SrvWinDrivs4" = "Start" = "0x00000002"
"HKLM\SYSTEM\ControlSet\Services\SrvWinDrivs4" = "Description" = "(blank)"
"C:\WINDOWS\System32\wbem\WtiSysSt.exe"

Trending

Most Viewed

Loading...