DFG bot 8.1.3
(Backdoor.Delf.lj)

by DFG

Written in Delphi, encrypted /compressed with tElock

Released in May 2004

Made in Romania

more versions


dropped file:

c:\WINDOWS\SYSTEM\SysTray813.com

size: 325.632 bytes
 
startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "MSFree813"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "SysTray813" 

does connect to IRC server "LosAngeles.CA.US.Undernet.Org"

MegaSecurity