LaDe 1.3
(Backdoor.Win32.Delf.kgb)
(Backdoor.Win32.Delf.kga for Server)

by ?

Written in Delphi

Released in January 2007

Made in Poland


Server:
dropped file:
c:\Documents and Settings\%user%\Desktop\LaDe 1.3\WINDOWSSystem32serw.exe
size: 392,192 bytes 
	
port: 21 TCP

added to registry:
HKEY_CURRENT_USER\SoftwareMicrosoftWindowsCurrentVersionRun "SERVER"
data: C:WINDOWSSystem32serw.exe 



tested on Windows XP
April 03, 2007

MegaSecurity