Hackarmy (c)
(Backdoor.Win32.Hackarmy.c)

by ?

Written in C, compressed with UPX

more versions


dropped file:
c:\WINDOWS\system32\win32serv.exe
size: 10,784 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Winsock32driver"
data: win32serv.exe 

attempts to connect to an IRC Server


tested on Windows XP
October 24, 2005

MegaSecurity