NetAngel 1.0
(Backdoor.Win32.Delf.qk)

by StTwister

Written in Delphi

Released in August 2004



Features:
-Fun stuff
-Windows functions(ShutDown, Activate Screen Saver, Empty Recycle Bin...)
-Clipboard Manager
-Window Manager
-Resolution Manager
-Process Manager
-Registry Manager
-File Manager (unavailable in v1.0)
-Message Manager
-Port Redirection
-Offline keylogger
-Application redirection (get console application output)
-Matrix chat (unavailable in v1.0)

-----------SERVER--------------

Startup options:
Registry: - HKEY_LOCAL_MACHINE-Run
	  - ActiveX	
Win.ini
System.ini
Explorer.exe bug - not working properly on al OS
---
Notifications:
-SIN
(Other will be added in later versions)
----

StTwister


Server:
dropped file:
c:\WINNT\system32\winlog.exe

size: 525.510 bytes
 
port: 4125 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{42CE4021-DE03-E4CC-EA32-40BB12E6015D} "StubPath"
data: C:\WINNT\system32\winlog.exe
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WinLogon"
data: C:\WINNT\system32\winlog.exe 

c:\winnt\system.ini, [boot] "shell"
value: C:\WINNT\system32\winlog.exe 
	
c:\winnt\win.ini, [windows] "run"
value: C:\WINNT\system32\winlog.exe 
	
tested on win2000

MegaSecurity