Come ToMe
(Backdoor.Win32.VB.aos)

by LavaBox

Released in March 2006

Written in Visual Basic

Made in Germany


Server:
dropped files:
c:\WINDOWS\dllhost.exe                                             Size: 258,048 bytes 
c:\WINDOWS\system32\taskmrg.exe                                    Size: 258,048 bytes 
c:\WINDOWS\system32\zlib.dll                                       Size: 53,248 bytes 
c:\Documents and Settings\All Users\Templates\Svchost.exe          Size: 258,048 bytes 
c:\Documents and Settings\%user%\My Documents\SystemControl.exe    Size: 258,048 bytes 

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "dllhost"
data: C:\WINDOWS\system32\dllhost.exe 

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "taskmrg"
data: C:\WINDOWS\system32\taskmrg.exe 

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windll"
data: C:\Documents and Settings\Kobayashi\My Documents\SystemControl.exe 



tested on Windows XP
June 06, 2006

MegaSecurity