Hackarmy (o)
(Backdoor.Win32.Hackarmy.o)

by ?

Written in C, compressed with UPX

Released in May 2004

more versions


dropped file:
c:\WINDOWS\SYSTEM\win32server.exe 

size: 14.368 bytes

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Winsock32driver"

Does connect to IRC server.
The dropper itself does melt

MegaSecurity