Evil Net POKET
(Not detected by AVP on August 15, 2004)

by whispering

Written in Delphi

Released in August 2004

more versions




Server:
dropped file:
c:\rundll.exe
size: 193.045 bytes 

port: 143, 200, 6213 TCP TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Microsoft Windows"
data: c:\rundll.exe 

MegaSecurity