Qzor
(Backdoor.Win32.Qzor)

by ?

Original Filename: HOTFIX_q300989EN_i386.exe

Written in Delphi, compressed with ASPack

Server Icon


dropped files:
c:\WINDOWS\mstask32.exe   Size: 46,080 bytes 
c:\WINDOWS\taskmgr.tsk    Size: 1 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Microsoft Task Manager"
data: C:\WINDOWS\mstask32.exe 



tested on Windows XP
April 18, 2005

MegaSecurity