BackLash (a)
(Backdoor.Win32.Backlash.101)

by Savage3

Written in Delphi

more versions


Server:
dropped file:
c:\WINDOWS\SYSTEM\msHtml.exe
size: 624.642 bytes 

port: 11831, 29559 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "MS HTML"
data: C:\WINDOWS\SYSTEM\msHtml.exe 



tested on Windows 98
March 29, 2005
 
MegaSecurity