Ice's Backdoor
(Constructor.Win32.Agent.a)
(Backdoor.Win32.Agent.ns for Server)

by Icingtaupe

Written in Assembler

Released in May 2005




Server:
dropped files:
c:\WINDOWS\system32\oobe\sysoobe.exe    Size: 9,728 bytes 
c:\WINDOWS\system32\oobe\ws_sk32.dll    Size: 5,632 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Gestionnaire de disques universel"
data: C:\WINDOWS\system32\oobe\sysoobe.exe 


tested o0n Windows XP
October 03, 2005
MegaSecurity