Author Topic: Avast finds this >> Win32:Delf-EPM (trj)  (Read 2759 times)

0 Members and 1 Guest are viewing this topic.

Chrisatrax

  • Guest
Avast finds this >> Win32:Delf-EPM (trj)
« on: June 11, 2007, 05:21:33 PM »
Hi Folks,

A buddy of mine sent me this email...

=====================================================
Chris,

wondered if you've dealt with this (Win32:Delf-EPM (trj).

Avast keeps finding this. It usually happens in pairs. It finds it twice
right after another. Both times I either have sent it to
quarantine or deleted it with Avast. Then I get an error message saying,
"cannot find microsoft.com", and icon appears on my desktop
briefly titled microsoft.com, and then disappears.
======================================================

I have googled this "Win32:Delf-EPM (trj)" without much luck, just a few translate this page site with the said trojan. Curious if anyone else has come across this trojen lately.

Thanks for any info on this little bugger (I assume)

Christopher

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: Avast finds this >> Win32:Delf-EPM (trj)
« Reply #1 on: June 11, 2007, 05:39:24 PM »
Hi Chrisatrax,

You can download the free X-Cleaner from here: http://www.xblock.com/download-freeware.php
against Win32:Delf-EPM(trj)

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89670
  • No support PMs thanks
Re: Avast finds this >> Win32:Delf-EPM (trj)
« Reply #2 on: June 11, 2007, 05:46:03 PM »
What is the infected file name, where was it found e.g. (C:\windows\system32\infected-file-name.xxx) ? 
Check the avast! Log Viewer (right click the avast icon), Warning section, this contains information on all avast detections.
What Operating System is he using ? is it up to date ?

Most Delf Trojans add a Startup entry:  Startup Entry Name, SysService  - Process Name, SysService.exe. Check for other unknown startup entries and report, see below.

Use Task Manager to End the Process SysService.exe if it exists. Also to end the startup entry, Windows Start, Run, type 'msconfig without the quotes, in the new window select the Startup Tab, find the SysService entry and uncheck it.

Malware that keeps coming back there may be other elements restoring it.
What is his firewall ?

If you haven't already got this software (freeware), download, install, update and run it, preferably in safe mode.
1. AVG anti-spyware (formerly Ewido) If using winXP. or a-Squared free if using win98/ME. Or SUPERantispyware Or Spyware Terminator
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security