Backdoor.Win32.Delf.cq
(Backdoor.Win32.Delf.cq)

by ?

Written in Delphi

more in this category




Backdoor.Win32.Delf.cq:
dropped files:
c:\WINDOWS\system32\dxservice.drv    Size: 263,557 bytes 
c:\WINDOWS\system32\SYSTEM.DBS       Size: 0 bytes 

port: 3746 TCP

added to registry:
HKEY_CLASSES_ROOT\drvfile\shell\open\command

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "DirectX For Microsoft� Windows"
data: C:\WINDOWS\System32\dxservice.drv 

HKEY_CLASSES_ROOT\drvfile "(Default)"
old data: Device driver 
new data: drvfile 	



	
tested on Windows XP
May 07, 2005

MegaSecurity