Backdoor.Win32.Delf.jh
(Backdoor.Win32.Delf.jh)

by ?

Original Filename unknown

Written in Delphi

more in this category



Backdoor.Win32.Delf.jh:
size: 135.036 bytes

dropped files:
c:\WINDOWS\system32\logon.exe  size: 135.036 bytes 
c:\WINDOWS\system32\z_ins.lg   size: 54 bytes 

port: 32123 TCP

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "logon.exe"
data: C:\WINDOWS\System32\logon.exe
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices "logon.exe"
data: C:\WINDOWS\System32\logon.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Kernel

tested on Windows XP 
06 November 2004

MegaSecurity