Back Webserver
(Backdoor.Win32.DeepThroat.20)

by ?

Released in February 1999


Back Webserver:
dropped files:
c:\WINDOWS\systray.exe         size: 312.082 bytes 
c:\WINDOWS\SYSTEM\acde.dat     size: 0 bytes 
c:\WINDOWS\SYSTEM\acdt.dat     size: 0 bytes 
c:\WINDOWS\SYSTEM\pddt.dat     size: 8 bytes 
c:\WINDOWS\SYSTEM\systemio.exe size: 19.712 bytes 

port: 6670, 2140, 3150 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "SystemTray"
old data: SysTray.Exe 
new data: c:\windows\systray.exe 

MegaSecurity