Coldlife 5.1
(Backdoor.IRC.ColdLife.51 for w32sock.bat)
(Backdoor.IRC.Fusion.20 for syst.bat)

by ColdLife

This is an Internet Relay Chat BOT/DDoS tool

Released in August 2002

more versions


Systray.exe:

size: 598.016 bytes

port: 113, 300, 27374 TCP

keys added:
HKEY_CURRENT_USER\Software\mIRC 
HKEY_CURRENT_USER\Software\mIRC\DateUsed 
HKEY_CLASSES_ROOT\.cha 
HKEY_CLASSES_ROOT\.chat 
HKEY_CLASSES_ROOT\ChatFile 
HKEY_CLASSES_ROOT\ChatFile\DefaultIcon 
HKEY_CLASSES_ROOT\ChatFile\Shell 
HKEY_CLASSES_ROOT\ChatFile\Shell\open 
HKEY_CLASSES_ROOT\ChatFile\Shell\open\command 
HKEY_CLASSES_ROOT\ChatFile\Shell\open\ddeexec 
HKEY_CLASSES_ROOT\ChatFile\Shell\open\ddeexec\Application 
HKEY_CLASSES_ROOT\ChatFile\Shell\open\ddeexec\ifexec 
HKEY_CLASSES_ROOT\ChatFile\Shell\open\ddeexec\Topic 
HKEY_CLASSES_ROOT\irc 
HKEY_CLASSES_ROOT\irc\DefaultIcon 
HKEY_CLASSES_ROOT\irc\Shell 
HKEY_CLASSES_ROOT\irc\Shell\open 
HKEY_CLASSES_ROOT\irc\Shell\open\command 
HKEY_CLASSES_ROOT\irc\Shell\open\ddeexec 
HKEY_CLASSES_ROOT\irc\Shell\open\ddeexec\Application 
HKEY_CLASSES_ROOT\irc\Shell\open\ddeexec\ifexec 
HKEY_CLASSES_ROOT\irc\Shell\open\ddeexec\Topic 

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "ColdLife - icmp" 
HKEY_CLASSES_ROOT\ChatFile\Shell\open\command "(Default)" 
HKEY_CLASSES_ROOT\irc\Shell\open\command "(Default)" 


MegaSecurity