Troj/Delf-LJ is a password stealing Trojan for the Windows platform.
When Troj/Delf-LJ is installed the following files are created:
<Common Files>\Microsoft Shared\Web Folders\ibm00001.dll
<Common Files>\Microsoft Shared\Web Folders\ibm00001.exe
<Common Files>\Microsoft Shared\Web Folders\ibm00002.dll
The file ibm00001.exe is detected as Troj/Torpig-C. The files ibm00001.dll and ibm00002.dll are also detected by Sophos as Troj/Delf-LJ. The DLL files contain functionalities to access the Internet, download, install and run new software, disable other applications and capture keystrokes.
The Trojan attempts to collect email and server password information, and submit the information via HTTP.
The following registry entries are created to run ibm00001.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Shell
<Common Files>\Microsoft Shared\Web Folders\ibm00001.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
explorer.exe "<Common Files>\Microsoft Shared\Web Folders\ibm00001.exe"