Backdoor.Win32.Delf.dz
(Backdoor.Win32.Delf.dz)

by ?

Original Filename unknown

Written in Delphi

more in this category


Backdoor.Win32.Delf.dz:
dropped files:
c:\WINDOWS\netstat.bat          Size: 133 bytes 
c:\WINDOWS\system32\actx.exe    Size: 26,146 bytes 

port: 1201, 2700 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\actx "StubPath"
data: C:\WINDOWS\System32\actx.exe 

attempts to connect to an IRC Server


related to Backdoor.Win32.Delf.dn



tested on Windows XP
May 24, 2005

MegaSecurity