Backdoor.Win32.Delf.ft
(Backdoor.Win32.Delf.ft)

by ?

Original Filename unknown

Written in Delphi, compressed with UPX

more in this category


dropped file:
c:\WINDOWS\csrss.exe
size: 193,536 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "csrss"
data: C:\WINDOWS\csrss.exe -i 

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "csrss"
data: C:\WINDOWS\csrss.exe -i 


tested on Windows XP
March 11, 2005

MegaSecurity