Naninf (a)
(Backdoor.Win32.Naninf.a)

by ?

Written in C (LCC), compressed with UPX



dropped file:
c:\WINDOWS\system32\svcnxp32.exe
size: 18.464 bytes 

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "WindowsXPserv"
data: svcnxp32.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WindowsXPserv"
data: svcnxp32.exe 

attempts to connect to an IRC server and join #drag


tested on Windows XP
January 02, 2004
	
MegaSecurity