by BloodWalker
Written in Delphi
Released in September 2001
|
Client:
port: 6712, 6713, 6714, 6715, 7722, 16712, 15206 TCP
6766, 6666, 8488, 15486, 16515, 50829, 47785, 47698, 1038, 61746, 61747, 61748, 43720 UDP
Server:
dropped files:
c:\WINDOWS\SYSTEM\boot.dat size: 34 bytes
c:\WINDOWS\SYSTEM\sjctl.exe size: 325.120 bytes
port: 6711, 6718,1031, 1234 TCP
6711, 6767, 8489, 29589, 16514, 1030, 6667, 15485 UDP
startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Boot Manager"
data: C:\WINDOWS\System\sjctl.exe
tested on Windows 98
January 16, 2005
MegaSecurity