GunBot (a)
(Backdoor.Win32.Gunbot.a)

by FRK

Written in Microsoft Visual C++, Compressed with tELock 0.98

more versions



dropped files:
%local dir%\GunBotbyFRK.exe
size: 44,544 bytes 

c:\WINDOWS\system32\wmedia.exe
sSize: 84,992 byte

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce "WindowsMedia"
data: C:\WINDOWS\System32\wmedia.exe -sys 

attempt to connect to an IRC Server located in Brazil




tested on Windows XP
April 27, 2005
MegaSecurity