Troj/Delf-SY is a Keylogging Trojan for the Windows platform.
Troj/Delf-SY contains functionality to communicate with a remote host via FTP.
When first run Troj/Delf-SY copies itself to <System>\wf.exe and creates the file <System>\keylog.dll.
The file keylog.dll is detected as Troj/Delf-SY.
The following registry entry is created to run wf.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WinFire
<System>\WF.exe
Registry entries are created under:
HKLM\SOFTWARE\WinFire\
Troj/Delf-SY is known to be dropped by Troj/Mdrop-Y.