Backdoor.Win32.Delf.dn
(Backdoor.Win32.Delf.dn)

by ?

Original Filename unknown

Written in Delphi


more in this category


dropped files:
c:\WINDOWS\netstat.bat          Size: 133 bytes 
c:\WINDOWS\system32\actx.exe    Size: 60,450 bytes 

port: 1202, 2701 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\actx "StubPath"
data: C:\WINDOWS\System32\actx.exe 

attempts to connect to an IRC Server located in Latvia and join #blah

related to Backdoor.Win32.Delf.dz



tested on Windows XP
May 16, 2005

MegaSecurity