Internet Exploiter 0.6
(Backdoor.Win32.IExploiter)

by Deviant Software

Written in Borland C++

Released in July 2003

Made in Russia


Server




Server:
dropped files:
c:\WINDOWS\system32\excl.iex       size: 68 bytes 
c:\WINDOWS\system32\firstserv.tmp  size: 60 bytes 

port: 12982 TCP

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "TaskManager"
data: C:\WINDOWS\System32\taskman.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\MacSoft



tested on Windows XP
March 23, 2005

MegaSecurity