BlueFire 0.50
(Backdoor.Win32.BlueFire.043)

by vinsa

Released in November 2001

Made in China

more versions


Server can be accessed by Telnet, sterm, cterm, Zmud, Ftp, IE, Netscape, Opera, Flashget, Cuteftp... 
Type "help" for commands.


Server:
dropped files:
c:\WINDOWS\SYSTEM\sysexpl.exe 
c:\WINDOWS\SYSTEM\tasksvc.exe  Size: 239.104 bytes 
c:\WINDOWS\SYSTEM\bfhook.dll 

port: 19191 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Network Services" 
HKEY_CLASSES_ROOT\txtfile\shell\open\command "(Default)" 

MegaSecurity