Backdoor.Win32.Delf.af
(Backdoor.Win32.Delf.af)

by ?

Original name unknown

Written in Delphi, compressed with ASPack

more in this category


Backdoor.Win32.Delf.af:
c:\WINDOWS\SYSTEM\system32.exe 

size: 290.304 bytes 

port: 21, 23, 32, 30, 122, 3000 TCP

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "system32" 

added:
c:\WINDOWS\SYSTEM\mail.sys 

MegaSecurity