Charge (b)
(Backdoor.Win32.Charge.b)

by ?

Written in Visual Basic

Other versions

Made in Germany


Server:
C:\WINDOWS\charge.exe
C:\WINDOWS\SYSTEM\COMMAND.exe

size: 173387 bytes

port: 37651, 58134, 27373 TCP

startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
c:\windows\system.ini

changes:
C:\AUTOEXEC.BAT
C:\WINDOWS\AUTOEXEC.BAT

new:
C:\WINDOWS\WINSTART.BAT
C:\WINDOWS\Y.BAT

MegaSecurity