C.I.A Cruel Intentionz 1.2 (a)
(Backdoor.Win32.Ciadoor.12.a)

by Alchemist

Written in Visual Basic

Released in September 2003

more versions


Server:
c:\WINDOWS\Csrss.exe 

size: 117.953 bytes 

port: 5888 TCP

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Runtime Process" 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices "Runtime
HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6017B} "StubPath"  
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Runtime Process" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices 
c:\windows\system.ini, [boot] "shell" 
c:\windows\win.ini, [windows] "load" 
c:\windows\win.ini, [windows] "run" 

file added:
c:\WINDOWS\SYSTEM\okl.okl 

registry added:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run "Runtime Process" 
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\windows\Run "Runtime Process" 


MegaSecurity