Backdoor.Win32.VB.aff
(Backdoor.Win32.VB.aff)

by ?

Original Filename: lbd.exe

Written in Visual Basic

Probably made in France

more in this category


dropped files:
c:\WINDOWS\system32\reghk.hdp     Size: 4,953 bytes 
c:\WINDOWS\system32\svc.pcb       Size: 33 bytes 
c:\WINDOWS\system32\svcp32.exe    Size: 487,424 bytes 
c:\WINDOWS\system32\taskHp.bqq    Size: 37,718 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "msvr32"
data: C:\WINDOWS\System32\svcp32.exe 

attempts to connect to an IRC Server

tested on Windows XP 
January 26, 2006

MegaSecurity