RTrjn
(Backdoor.Win32.VB.cb)

by Rufous

Written in Visual Basic

Released in May 2002

Made in Poland



Server:
Dropped file:
c:\WINDOWS\SYSMGR.EXE
size: 40.960 bytes
 
port: 1001, 1002 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Sysmgr"
data: C:\WINDOWS\SYSMGR.EXE 

tested on Windows XP

MegaSecurity