Pitfall 2.1
(Backdoor.Win32.PitFall.21)

by IntrudeR

Released in August 2000

Made in Brazil

more versions




Server:
dropped files:
c:\WINDOWS\WININIT.INI         size: 10 bytes 
c:\WINDOWS\SYSTEM\PITFALL.EXE  size: 180.736 bytes 

startup:
HKEY_CURRENT_USER\Software\Mirabilis\ICQ\Agent\Apps\Hbgbosocgj "Path"
data: C:\WINDOWS\SYSTEM\PITFALL.EXE 

HKEY_CURRENT_USER\Software\Mirabilis\ICQ\Agent\Apps\Hbgbosocgj "Startup"
data: C:\WINDOWS\SYSTEM\ 

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "LoaderW32"
data: C:\WINDOWS\SYSTEM\PITFALL.EXE 

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices "LoaderW32"
data: C:\WINDOWS\SYSTEM\PITFALL.EXE 

Server does kill some Anti-Virus Programs (AVP)

tested on Windows 98
November 08, 2004

MegaSecurity