Sophos

Troj/Delf-LJ

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 26 September 2005 01:46:08 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

Troj/Delf-LJ is a password stealing Trojan for the Windows platform.

When Troj/Delf-LJ is installed the following files are created:

<Common Files>\Microsoft Shared\Web Folders\ibm00001.dll
<Common Files>\Microsoft Shared\Web Folders\ibm00001.exe
<Common Files>\Microsoft Shared\Web Folders\ibm00002.dll

The file ibm00001.exe is detected as Troj/Torpig-C. The files ibm00001.dll and ibm00002.dll are also detected by Sophos as Troj/Delf-LJ. The DLL files contain functionalities to access the Internet, download, install and run new software, disable other applications and capture keystrokes.

The Trojan attempts to collect email and server password information, and submit the information via HTTP.

The following registry entries are created to run ibm00001.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Shell
<Common Files>\Microsoft Shared\Web Folders\ibm00001.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
explorer.exe "<Common Files>\Microsoft Shared\Web Folders\ibm00001.exe"

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer