BirdSPY (a) server
(Backdoor.Win32.BirdSpy.a)

by Chiu a.k.a Birdman

Written in Visual C++, compressed with ASPack

Released in December 2000

Made in Taiwan

more versions



Server:
dropped files:
c:\WINDOWS\Ndapi32c.dll 
c:\WINDOWS\winstart.bat 
c:\WINDOWS\ÿ.bat 
c:\WINDOWS\Winbime.scr         Size: 27.648 bytes 
c:\WINDOWS\SYSTEM\WinApp32.exe Size: 27.648 bytes 

port: 47878 TCP

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "User Screen" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Wldap32.dll" 

MegaSecurity