Ghost-Bot 0.55
(Backdoor.Win32.Delf.ma)

by Positron

Compressed with UPX, written in Delphi

Other versions



v0.55
   -!mirccmd added,
   -bug fixed in "commandprefix",

Positron


GhostBot:
dropped file:
c:\WINDOWS\wLVH4Q.exe
size: 34.515 bytes

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "SWNETSUP"
data: C:\WINDOWS\wLVH4Q.exe  

does (try to) connect to an IRC server

tested on Windows XP
09 November 2004

MegaSecurity