Stealth Shutdown
(Trojan.Win32.Delf.ip for Server)

by ReSoil

Written in Delphi, compressed with ASPack

Released in September 2003




Server:
dropped file:
c:\WINDOWS\SYSTEM\service.exe 

size: 99.328 bytes

port: 53785 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Background Service" 

MegaSecurity