Backdoor.Win32.Delf.zm
(Backdoor.Win32.Delf.zm)

by ?

Written in Delphi, compressed with Petite

more in this category


dropped file:
c:\WINDOWS\system\msrecallsys.exe
size: 194,609 byte

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "msrecallsys"
data: c:\windows\system\msrecallsys.exe 

Attempts to connect to an IRC Server
Probably made in Brazil

tested on Windows XP
December 28, 2005 

MegaSecurity