JoinMe 1.3.1.38
(Backdoor.Win32.Delf.fw)

by Elias Konstadinidis

Written in Delphi, compressed with UPX

more versions


dropped files:
%local dir%\JoinMe.conf     size: 316 bytes 
%local dir%\Operators.conf  size: 0 bytes 

added to registry:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "directx.exe" 

HKEY_LOCAL_MACHINE\Software\ColdVision "update" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Ras\Tapi Devices 
	
	
	
tested on Windows XP

MegaSecurity