Remote PC
(Backdoor.Win32.Dirtxt)

by koby

Written in C, source included

Released in August 2003

Made in Russia





Server:
dropped file:
c:\WINDOWS\winlogin.exe 

size: 25.002 bytes 

port: 4950 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "WindowsInit" 

added:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\&Programs\Menu 

MegaSecurity