Trojan Delf – ressdt.exe – 05f15e08a791f41909942acbceeeb1c1

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Trojan Delf
Also known as: Trojan Banker, Backdoor Hupigon
SHA256: 80db8f2fb891c062f0d5d3e7f216667905c4539524d69aca9f2d2bbf5c36b652
SHA1: 74488fae3a03df88c965963f256837a10b7a60bb
MD5: 05f15e08a791f41909942acbceeeb1c1
File size: 584704 bytes

Created files:

%SysDir%\ressdt.exe – Trojan Delf
%SysDir%\ressdt.sys – Trojan Delf
%Temp%\RarSFX0\b.bat – Trojan Delf
%Temp%\RarSFX0\p1.exe – Trojan Delf
%Temp%\RarSFX0\unpack.exe – Trojan Delf
%Temp%\winword.exe – Trojan Delf

Trojan Delf created autostart registry keys:

HKLM\Software\Microsoft\Active Setup\Installed Components\{83b5f312-b0f6-11d0-94ab-0080c74c7e95}\StubPath: %WinDir%\web\wallpaper.pif
HKLM\Software\Microsoft\Active Setup\Installed Components\{83b5f312-b0f6-11d0-94ab-0080c74c7e95} : Microsoft Windows Webpaper

Leave a Reply