Whacky
(Backdoor.Win32.Whacky)

by ?

Written in Delphi

Made in Germany


dropped file:
c:\WINDOWS\uninstall.exe
size: 425.472 bytes 

port: 513 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices "(Default)"
data: C:\WINDOWS\uninstall.exe 

c:\windows\win.ini, [windows] "load"
value: C:\WINDOWS\uninstall.exe 


tested on Windows 98
December 22, 2004

MegaSecurity