Remote Hack 1.6 Beta
(Backdoor.Win32.RemoteHack.16.b)

By WishMaster

Server is written in Delphi

Released in December 2002

Made in Brazil

more versions





Server:
dropped file:
c:\WINDOWS\SYSTEM\rundll128.exe 

size: 571.392 bytes 

port: 51985 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Microsoft Winrun" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices "Microsoft Winrun" 

added:
c:\WINDOWS\SYSTEM\rundll64.dll 

MegaSecurity