Backdoor.Win32.VB.e
(Backdoor.Win32.VB.e)

by ?

Original name unknown

Written in Visual Basic

Released in April 2001

more in this category


Dropped file:
c:\WINDOWS\SYSTEM\703DLL.EXE 

size: 110.592 bytes 
 
port: 31900 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Gtgpvyhik" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices 
HKEY_CURRENT_USER\Software\Mirabilis\ICQ\Agent\Apps\Bqal 

server sends a notify with ICQ

MegaSecurity