Backdoor.Win32.Delf.yt
(Backdoor.Win32.Delf.yt)

by ?

Written in Delphi, compressed with UPX

Probably made in Brazil

more in this category


message box displayed by backdoor

size: 189,952 bytes

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_STISVC\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_STISVC\0000\Control

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "aaReg"
data: C:\WINDOWS\System32\stil21.exe 0 


tested on Windows XP
November 18, 2005

MegaSecurity