Backdoor.Win32.Delf.gf
(Backdoor.Win32.Delf.gf)

by ?

Original Filename unknown:

Written in Delphi

Released in September 2003

Made in Brazil

more in this category


Backdoor.Win32.Delf.gf:
size: 821.248 bytes

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Kernel Protocol" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Timer Syncronize" 

dropped files:
c:\mskrn.sys 
c:\WINDOWS\mskr32.exe 
c:\WINDOWS\SYSTEM\mswin.exe 

Tries to connect to a specified IRC server to join channel #Brasil and listen for commands

MegaSecurity