BirdSPY (b) server
(Backdoor.Win32.BirdSpy.b)

by Chiu a.k.a Birdman

Written in Visual C++, compressed with ASPack

Released in DEecember 2000

Made in Taiwan

more versions



Server:
dropped files:
c:\WINDOWS\Ndapi32K.dll 
c:\WINDOWS\winstart.bat 
c:\WINDOWS\ÿ.bat 
c:\WINDOWS\SYSTEM\WinSock.exe   Size: 27.648 bytes 
c:\WINDOWS\Winbife.scr          Size: 27.648 bytes 

port: 50829 TCP

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "MS-Screen" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run 

MegaSecurity