Hackarmy (p)
(Backdoor.Win32.Hackarmy.p)

by ?

Written in C, compressed with PECompact

Released in June 2004

more versions


dropped file:
c:\WINDOWS\SYSTEM\ZoneLockup.exe 

size: 15.872 bytes

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Winsock32driver"

The dropper itself does melt

MegaSecurity