Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Protection available since | 26 September 2005 01:46:08 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Delf-LJ is a password stealing Trojan for the Windows platform.
When Troj/Delf-LJ is installed the following files are created:
<Common Files>\Microsoft Shared\Web Folders\ibm00001.dll
<Common Files>\Microsoft Shared\Web Folders\ibm00001.exe
<Common Files>\Microsoft Shared\Web Folders\ibm00002.dll
The file ibm00001.exe is detected as Troj/Torpig-C. The files ibm00001.dll and ibm00002.dll are also detected by Sophos as Troj/Delf-LJ. The DLL files contain functionalities to access the Internet, download, install and run new software, disable other applications and capture keystrokes.
The Trojan attempts to collect email and server password information, and submit the information via HTTP.
The following registry entries are created to run ibm00001.exe on startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Shell
<Common Files>\Microsoft Shared\Web Folders\ibm00001.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
explorer.exe "<Common Files>\Microsoft Shared\Web Folders\ibm00001.exe"
