Backdoor.Win32.Delf.aew
(Backdoor.Win32.Delf.aew)

by ?

Original name unknown

Written in Delphi, compressed with UPX

more in this category


dropped files:
c:\WINDOWS\system32\error.vbs     Size: 43 bytes 
c:\WINDOWS\system32\winmgr.exe    Size: 200,704 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "winmgr.exe"
data: C:\WINDOWS\System32\winmgr.exe 

attempts to connect to an IRC Server




tested on Windows XP
March 26, 2006

MegaSecurity