CZesiA
(Backdoor.Win32.Delf.auj)

by Karol

Written in Delphi

Released in August 2004

Made in Poland


Server:
dropped files:
c:\WINDOWS\mojabaza.exe                    size: 693.760 bytes 
c:\WINDOWS\SYSTEM\confoc.drv               size: 693.760 bytes 
c:\WINDOWS\SYSTEM\bsecze\4804 142503.txt   size: 0 bytes 

port: 800, 6666 TCP

Added to registry:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "mswinconf"
data: C:\WINDOWS\SYSTEM\confoc.drv 

MegaSecurity