SuperStar 1.0 v2
(Backdoor.Win32.VB.xk for Client)
(Backdoor.Win32.Ciadoor.i)

by SHut

Written in Visual Basic

Released in February 2004

Made in France

more versions




Server:
dropped files:
c:\Documents and Settings\%user%\Start Menu\Programs\Startup\Winup15.exe
size: 393,216 bytes 

c:\WINDOWS\system32\Winup15.exe
size: 393,216 bytes 


port: 25525, 30250 TCP

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows "run"
data: C:\WINDOWS\system32\Winup15.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "lsass"
data: C:\WINDOWS\system32\Winup15.exe 

c:\Documents and Settings\%user%\Start Menu\Programs\Startup\Winup15.exe



tested on Windows XP
January 30, 2005

MegaSecurity