Kaju BackDoor
(Trojan.Win32.Agent.bqyk)
(not-a-virus:RemoteAdmin.Win32.WinVNC.j)

by Kaju

Released in November 2008

Made in Brazil


Server
c:\WINDOWS\inf\1010\services.exe    Size: 627,259 bytes 
c:\WINDOWS\system32\dd.dll          Size: 810 bytes 
c:\WINDOWS\system32\ultravnc.ini    Size: 683 bytes 

Added to Registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Services"
Data: C:\WINDOWS\inf\1010\services.exe 

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile "DisableNotifications"
Data: 01, 00, 00, 00 

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile "DoNotAllowExceptions"
Data: 00, 00, 00, 00 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile "DisableNotifications"
Data: 01, 00, 00, 00 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile "DoNotAllowExceptions"
Data: 00, 00, 00, 00 


Tested on Windows XP
November 20, 2008

MegaSecurity