MIAH 1.21
(Backdoor.Win32.Hami.12 for Client)
(Not detected by KAV on February 17, 2008 for Server)

by ZsysTeam

aka Make It At Home

Compressed with ASPack

Released in December 2003

Made in China




Server:
Dropped file:
c:\WINNT\system32\miahserver.exe

size: 90.112 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MIAHSERVER\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MiahServer\Enum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MiahServer\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MIAHSERVER\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MiahServer\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MiahServer\Security

tested on Win2000

server icon is visible in the taskbar

MegaSecurity