Backdoor.Win32.Delf.kq
(Backdoor.Win32.Delf.kq)

by ?

Real name is unknown

Written in Delphi, compressed with ASPack

Made in China

more in this category


Server:
dropped file:
c:\WINDOWS\system32\Sysexplr.exe
size: 82,944 bytes 

port: 13141 TCP

startup:
HKEY_CLASSES_ROOT\*\Shell\open\command



tested on Windows XP
March 21, 2005

MegaSecurity