W32/Delf.JQ!tr.spy
Analysis
Title: Installed Successfully
Message:
Thank Q for Upgrading Patch. This Patch Enables Security to Your Computer
Now the bug called .gif *.gif are fixed with this patch...
For more information send us email to support@limewire.com with your Orderid
Autostart Mechanism
HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{pycuvsdp-kaki-ebkr-egtg-gjcuiewwdvdm}
StubPath = "undefinedSYSTEMundefined\vedqg.exe"
Backdoor and/or Trojan Behavior
HKEY_CURRENT_USER\Software\Adobe\SUBG
SUB = "undefinedSYSTEMundefined\vedqg.exe"
SUBZ = "pdvsf.jyg"HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\srservice
Start = dword:00000004
This disables the System Restore Service.
Telemetry
Detection Availability
FortiGate | |
---|---|
Extreme | |
FortiClient | |
Extended | |
FortiMail | |
Extended | |
FortiSandbox | |
Extended | |
FortiWeb | |
Extended | |
Web Application Firewall | |
Extended | |
FortiIsolator | |
Extended | |
FortiDeceptor | |
Extended | |
FortiEDR |