NastyXP 1.1 Beta 2
(Backdoor.Win32.Delf.air)

by BBOYMARIO

Written in Delphi

Released in September 2005

Made in Poland

more versions


Server:
dropped file:
c:\WINDOWS\Internet.exe
size: 899,146 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "services"
data: C:\WINDOWS\services.exe 

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List "Internet"
data: Internet:*:Enabled:Internet 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List "Internet"
data: Internet:*:Enabled:Internet 


tested on Windows XP
September 17, 2005	

MegaSecurity