Threat Database Trojans Trojan.Delf

Trojan.Delf

By CagedTech in Trojans

Threat Scorecard

Ranking: 5,339
Threat Level: 90 % (High)
Infected Computers: 20,712
First Seen: July 24, 2009
Last Seen: April 21, 2024
OS(es) Affected: Windows

Trojan.Delf is a threat that intercepts the Internet traffic and compromises the system security in a big way. If the computer users encounter this Trojan on their systems, they should keep in mind that there may be other threats on their machine as well. Trojan.Delf is often installed by other threats on the targeted computers, but it also can be a product of a drive-by download under the file name 'bot_unencrypted.exe.' When Trojan.Delf finds its way onto a computer, it changes its name once the installation is complete.

The Trojan.Delf infection ends up being installed in the System32 folder, where it creates a copy of itself bearing the name WtiSysST.exe. Trojan.Delf is then installed as a system drive in an attempt to avoid detection by the usual security products. Trojan.Delf also modifies a Registry sub-key, making it start whenever the infected computer is booted up. Once the installation is complete, Trojan.Delf connects to its remote server for updates and instructions from its developers.

Trojan.Delf will attempt to obtain determined information, such as cookies, browsing history, user names and passwords by intercepting secure and insecure Internet data (HTTPS and HTTP). Once that data is saved, it is later uploaded to a remote server where the attackers may use it to further their scheme.

Trojan.Delf hides from security products by injecting its code into system processes, such as lsass.exe and svchost.exe. Trojan.Delf also may modify the system settings and trick websites to think that computer users are browsing via Mozilla Firefox, Apple Safari, Google Chrome or Avant Browser. This is done to allow Trojan.Delf to avoid removal for as long as possible by obfuscating its presence in a system.

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
AVG Hider.QFR
Fortinet W32/ZAccess.K
Microsoft TrojanDropper:Win32/Sirefef.B
Antiy-AVL Virus/Win32.ZAccess.gen
Symantec Packed.Generic.344
NOD32 Win32/Sirefef.DA
K7AntiVirus Virus
McAfee Generic.dx!bd3j
AVG Agent_r.BEC
Fortinet W32/ZAccess.K!tr
Ikarus Rootkit.Win32.ZAccess
Antiy-AVL Virus/Win32.ZAccess
AntiVir TR/Conjar.187904.5
Comodo TrojWare.Win32.Rootkit.ZAcces.HL
BitDefender Gen:Heur.Conjar.11

SpyHunter Detects & Remove Trojan.Delf

File System Details

Trojan.Delf may create the following file(s):
# File Name MD5 Detections
1. wh.exe 681605a644d93853b6dcad2fb0b759c0 3,741
2. hub.exe e28b8169e6766a795a6e0a4b1faece69 2,256
3. scvhost.exe 42ad0d9c51373baa39b9c04b303e310a 268
4. jsheded.exe de2b3d20a8cf3fc7d75f73c3ee757148 151
5. Usermode.exe 2adec0cae94520d5700c45c7a7b982e2 129
6. scvhost.exe 114ffd59bb1f5d90954480a92d056712 80
7. scvhost.exe cd1274a482e9850cfceeafa5401d8cf4 42
8. scvhost.exe 68d690a918aa56a26b0846f9be414514 17
9. n. 5e28c03100586c76bdaa42c9467ec5f8 11
10. n. c1e52127aa9b54c664ac4ca1efc4529b 8
11. dwm.exe 8718222259cc28fc98d4c619b7782844 8
12. svhost.exe b2c187c97295a6828527059f49ccf19a 6
13. dwm.exe 4fa7fdb460e0b7da4c80ebafd357ad74 6
14. batszxye.exe 7a2ccfa78bace5cd84372aa0be3cff03 4
15. n. 55e367336d30de18020f72a4a6671e5c 4
16. scvhost.exe 37231907e7c261841d5db74d907811f5 4
17. iupdater.exe 62c70a0a68ffc3c7718309957a06564f 3
18. asktbarx.dll 15594e754153e0e4fd3db6e8f5ed3abe 3
19. nqnqe.exe cac15bbccd5b708290a44086f72deb7d 2
20. 0.5741384901339003.exe be0bdbc56b875f2645e594d35c006119 2
21. GoogleApp.exe 2a650fca7830ce1d4217421378d55835 2
22. apptj.exe 73f666d9d800c251c2f54ccb90642730 2
23. apptj.exe 8f5a1e1d818dc3a3e073fc62c32e22c1 2
24. apptj.exe 961c93999ab5bb2a37cc6e4e9609f1d7 1
25. apptj.exe 5da41f7d671ee383b8d427e8f470a365 1
26. apptj.exe 97040ed47a7715f6eb37b1207dfd9d64 1
27. file.exe ceb88fed80fd4990f9ae09d6a353833f 0
28. file.exe 21189693a4d14fb324656b8cd92d30f8 0
29. file.exe d58d090a6e4b8657a0abea0a0fda60fc 0
More files

Registry Details

Trojan.Delf may create the following registry entry or registry entries:
Regexp file mask
%PUBLIC%\Documents\vtr.exe

Directories

Trojan.Delf may create the following directory or directories:

%APPDATA%\WHService

Related Posts

Trending

Most Viewed

Loading...