Rage 1.0
(Backdoor.Win32.Ragedoor.10)

by ?

Written in Borland Delphi, compressed with ASPack


dropped file:
c:\WINDOWS\Sys32.exe

size: 150.528 bytes 

port: 1313 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "SysCheck"
data: C:\WINDOWS\Sys32.exe 




tested on Windows 98
April 08, 2005

MegaSecurity