Backdoor.Win32.Delf.i
(Backdoor.Win32.Delf.i)

by Dmitry

Original name unknown, internal file name: "inter.exe"

Written in Delphi

Released in April 2002

more in this category


message shown

Dropped file:
c:\Program Files\inter.com 

size: 534.528 bytes 

port: 1324, 9846 TCP

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "inter" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "inter" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices 
c:\windows\win.ini, [windows] "run" 
c:\windows\win.ini, [windows] "load" 

added:
c:\Autorun.inf 

MegaSecurity