Spirit 3:b1
(Backdoor.Win32.Delf.abi)

by iciko

Written in Delphi

Released in June 2005

more versions


 - Beta 1:
    - Fixed recving buffer bigger than 8192
    - Fixed downloading
    - Fixed 9x DLL
    - Fixed ListView redrawing
    - Plugin is deleted on uninstall
    - Added window management
    - Added service management
    - Added server melt
    - Added ID
    - Shaved off 72 bytes
	
iciko


Server:
dropped file:
c:\WINDOWS\system32\msvrhost32.exe
size: 1,661 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2A202488-F02D-11cf-64CD-1123AFEECF20} "StubPath"
data: C:\WINDOWS\System32\msvrhost32.exe



tested on Windows XP
June 14, 2005

MegaSecurity