Little Witch 6.1 (aa) Server
(Backdoor.Win32.LittleWitch.61.aa)

by Axlito

Written in Delphi

Released in May 2004

Made in Argentina

more versions


Server:
dropped files:
c:\WINDOWS\usr.dat             size: 420 bytes 
c:\WINDOWS\SYSTEM\Rundll.exe   size: 41.180 bytes

port: 31320 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Rundll"

registry added:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "EnableAutodial" 
HKEY_CURRENT_USER\Software\Msn "Date"

MegaSecurity