BlueFire 0.36
(Backdoor.Win32.BlueFire.036)

by vinsa

more versions


Chinese Trojan.
Server can be accessed by Telnet, sterm, cterm, Zmud, Ftp, IE, Netscape, Opera, Flashget, Cuteftp... 
Type "help" for commands.



Server:
dropped file:
C:\windows\system\tasksvc.exe

size: 580 KB

port: 19191 TCP

startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run	 
HKCR\txtfile\shell\open\command

MegaSecurity