StrikeBackdoor 048 BETA 1
(Not detected by KAV on March 20, 2006)

by Bartlomiej B

Compressed with UPX

Released in March 2005

Made in Poland

more in this category




Server:
dropped files:
c:\WINDOWS\error.bat               size: 208 bytes 
c:\WINDOWS\system32\DirectX3D.dll  size: 238,592 bytes 
c:\WINDOWS\system32\winlong.exe    size: 238,592 bytes 

port: 6868, 6869 TCP

added to registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Winlong"
data: C:\WINDOWS\system32\winlong.exe 

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List "C:\Documents and Settings\Kobayashi\Desktop\Strike\Server.exe"
data: %trojan path%\Server.exe:*:Enabled:PORT P2P 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List "C:\Documents and Settings\Kobayashi\Desktop\Strike\Server.exe"
data: %trojan path%\Server.exe:*:Enabled:PORT P2P 



tested on Windows XP
March 26, 2005