Threat Search: 

ThreatExpert's Statistics for Trojan.Win32.Delsha [Ikarus]:

Trojan.Win32.Delsha [Ikarus] is also known as:
Threat AliasNumber of Incidents
Generic PUP.x [McAfee]2
Constructor/EESBinder.573440 [AhnLab]1
Mal/Generic-A [Sophos]1
MultiDropper-ED.cfg [McAfee]1
PWS-Fakeyah [McAfee]1
Reboot-AA [McAfee]1
Troj/Delsha-C [Sophos]1
Troj/EESbind [Sophos]1
Troj/Fakeyah-B [Sophos]1
TROJ_EESBINDER.B [Trend Micro]1
Trojan Horse [Symantec]1
Trojan.Delsha [PC Tools]1
Trojan.Delsha [Symantec]1
Trojan.FakeLogin.B [PC Tools]1
Trojan.FakeLogin.Gen [Symantec]1
Trojan.Win32.Delf.guz [Kaspersky Lab]1
Trojan.Win32.Delsha.c [Kaspersky Lab]1
Trojan.Win32.FakeLogin.b [Kaspersky Lab]1
Trojan.Win32.VkHost.da [Kaspersky Lab]1
Trojan:Win32/Fakelogin.B [Microsoft]1
Trojan-Dropper.EESbinder!sd5 [PC Tools]1
Trojan-Dropper.Win32.EESbinder [Kaspersky Lab]1
TrojanDropper:Win32/EESbinder [Microsoft]1
Win-Trojan/Delsha.20480 [AhnLab]1
Win-Trojan/Fakelogin.416770 [AhnLab]1

Trojan.Win32.Delsha [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
Russian Federation7
Spain3
France2
Japan2
Taiwan2
Brazil1
Germany1
Indonesia1
United Kingdom1

Trojan.Win32.Delsha [Ikarus] is known to be created as:
%ProgramFiles%\a8gsdsapp\bmptojpg.dll
%System%\3251\converter.dll
%System%\ime\unispim\upcfgwiz.exe
%System%\rundl32.exe
%Temp%\dd.exe
c:\winnt\system32\infsrv.exe
Notes:
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).