Lamers Death 2.7 server
(Backdoor.Win32.Death.27.b)

by FreeLoader

Written in Delphi

Released in october 2003

Made in Russia

more versions


Server:
port: 30003 TCP

dropped files:
c:\WINDOWS\SYSTEM\runexec.dll   size: 8.704 bytes 
c:\WINDOWS\SYSTEM\winsock.exe   size: 271.747 bytes

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "winsock.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "winsock.exe"
c:\windows\system.ini, [windows] "Load"

registry added:
HKEY_LOCAL_MACHINE\Software\Microsoft\Socket\Settings

MegaSecurity