Net-Devil 1.5
(Backdoor.Win32.NetDevil.15)

by Nilez

Written in Delphi

Released in June 2002

more versions


Server:
dropped file:
C:\WINDOWS\SYSTEM\KERNEL32.DLI 

size: 659.968 bytes

port: 901 TCP

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "kernel32" 


Added:
HKEY_CLASSES_ROOT\.dlI "(Default)" 
HKCR\dlIfile\shell\open\command "(Default)" 

MegaSecurity