R0xR4t 1.1
(Backdoor.Win32.Roxrat.11)

by c400s

Written in Delphi

Released on August 4, 2002

Made in Brazil

more versions





Server:
C:\WINDOWS\MSRUNNER.EXE
C:\WINDOWS\SYSTEM\MZSYSTEM.EXE 

size: 595 KB

port: 15000, 60551, 60552 TCP

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Microsoft Runner" 
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices "Microsoft Runner" 
HKCR\txtfile\shell\open\command "(Default)" 
c:\windows\system.ini, [boot] "shell" 
c:\windows\win.ini, [windows] "run" 

MegaSecurity