akosch
(Backdoor.Win32.Delf.go)

by akosch

Written in Delphi

Released in July 2002

Made in Germany

more versions


Server:
dropped file:
c:\WINDOWS\WebBrowser.exe
size: 302.592 bytes
 
port: 1987 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Browser"
data: C:\WINDOWS/WebBrowser.exe 

startpage browser is changed to: http://www.microsoft.com
	
tested on Windows 98

MegaSecurity