Ghost Stolker 1.0 Beta1
(Backdoor.Win32.VB.gen for Server)

by Mobman

Written in Visual Basic

Released in May 2007

Made in France

Other versions

 





Server:
dropped file:
c:\WINDOWS\system32.exe
size: 4 bytes 

port: 876 TCP

Added to registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "registry32"
data: C:\WINDOWS\system32.exe 




tested on Windows XP
May 28, 2007

MegaSecurity