Explorer remoto (a)
(Backdoor.ExplorerRemoto.a)

by TheJack

Written in Visual Basic

Released in July 2004

Made in Argentina





Server:
dropped file:
c:\SERVER PARA BAJAR ARCHIVOS.exe
 
size: 45.056 bytes 

port: 8000, 8001, 8086, 8087 TCP

added to registry:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "MyApp"

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "SERVER PARA BAJAR ARCHIVOS"
data: \SERVER PARA BAJAR ARCHIVOS.exe 

MegaSecurity