Remote Fuckdown
(Backdoor.Win32.Delf.mts)

by Eddy14

Written in Delphi, Source included

Released in September 2006


Server:
dropped files:
c:\WINDOWS\Windows Firewall ©.exe
size: 388,608 bytes 

port: 1600 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Firewall ©"
data: C:\WINDOWS\Windows Firewall ©.exe 




Tested on Windows XP
October 14, 2006

MegaSecurity