PaSzCzuS 2.0-rc2
(Backdoor.Win32.Pazus.20)
(Backdoor.Win32.Pazus.18 for edit.exe)

by Neo

Written in Delphi

Released in January 2004

Made in Poland

more versions


Server:
dropped file:
c:\WINDOWS\SYSTEM32\syscfg32.exe 

size: 790.016 bytes 

port: 26745, 26746, 27747 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Configuration Loader" 

registry added:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\LANChat "Sciezka" 

MegaSecurity