Pipes
(Backdoor.Win32.Pipes)

by ?

Written in Assembly, source included

Released in march 2000


;============================================================================
; Demo Win32 NetBus worm.
;
; This is a simple Internet worm using NetBus servers to propagate.
; The worm periodically scans it's own (class C) subnet for NetBus 1
; servers, and uploads itself to the hosts that have the server running,
; after which the uploaded copy will be remotely executed.
;
; The only reason why I targetted NetBus 1 was because it's the only
; backdoor trojan I had on my harddrive. It would have been better to
; target Sub-Seven servers, as these are far more widespread (and more
; powerful aswell).
;
; Oh yeah, it also uses Happy99 to travel..
;
; T-2000/IR, March 2000.


Server:
C:\WINDOWS\SYSTEM\SKA.EXE

size: 6.144 bytes

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

MegaSecurity