Backdoor.Win32.Delf.ix
(Backdoor.Win32.Delf.ix)

by ?

Original Filename unknown

Written in Delphi

more in this category


Backdoor.Win32.Delf.ix:
size: 559.616 byte

dropped file:
c:\WINDOWS\sistry.exe
size: 559.616 bytes

deleted:
c:\WINDOWS\SYSTEM\MSCONFIG.EXE
 
port: 21 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "sistry"
data: C:\WINDOWS\sistry.exe 

tested on Windows 98

MegaSecurity