A-311 server (g)
(Backdoor.Win32.Haxdoor.g)

by Corpse

Released in August 2003




Server:
c:\WINDOWS\SYSTEM\status.dll 

size: 19.968 bytes
 
port: 16661 TCP

startup:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MPRServices\TestService 

added:
c:\WINDOWS\SYSTEM\snowx.ini 
c:\WINDOWS\SYSTEM\status.dll 
c:\WINDOWS\SYSTEM\tage32.sys 

MegaSecurity