Poltergeist 1.1 (b)
(Backdoor.Win32.Poltergeist.b)
(Trojan-Dropper.Win32.Exebundle.27 for installer)

by Trainwreck

Written in Visual Basic

Released in October 2003

more versions


Installer:
size: 402.628 bytes

server:
c:\WINDOWS\NAVscan.exe 

size: 20.480 bytes  

port: 12001, 12002, 12003, 12004, 12005, 12007, 12008, 12010, 12016, 33156, 55165, 55166 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "ccrs.exe" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Explorer.exe" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "MSDOS" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices 

registry added:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" 

files added:
c:\WINDOWS\Trainwreck.dll 
c:\WINDOWS\server.exe 
c:\WINDOWS\NAVscan.exe 

MegaSecurity