Posejdon
(Backdoor.Win32.Delf.azh)

by Smark

Written in Delphi

Released in January 2007

Made in Poland


Server
dropped files:
c:\plik.exe                                      Size: 671,744 bytes 
c:\Program Files\Internet Explorer\tasmgr.exe    Size: 671,744 bytes 

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "tasmgr"
data: C:\Program Files\Internet Explorer\tasmgr.exe 




tested on Windows XP
January 11, 2007

MegaSecurity