DocTor 0.13
(Backdoor.Win32.Torent.013)

by DocTor

Written in Delphi

Released in June 2004

Made in Poland


server


Client does alter home page
port: 11, 16, 17, 18, 19, 22, 31, 52, 101, 102, 103, 120, 107, 202, 230, 231, 232, 300, 303, 305, 350, 137, 1400, 113, 114 TCP


Server:
port: 9, 10, 12, 13, 15, 21, 100, 104, 105, 106, 200, 212, 290, 304, 136, 112 TCP

dropped file:
c:\WINNT\TRAY_.EXE 
size: 648,704 bytes

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Tray Control 6.0" 
data: C:\WINDOWS\TRAY_.EXE

tested on win2000

MegaSecurity