Yet Another Trojan 2.24 Server
(Backdoor.Win32.Bedienks.224)

by HSE

Written in Visual Basic

Released in September 2001

Made in Germany

more versions


Server:
c:\WINDOWS\charge.exe 

size: 375.557 bytes 

port: 37673 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices "Batterieanzeige" 
c:\windows\system.ini, [boot] "shell" 
c:\windows\win.ini, [windows] "run" 

added:
c:\WINDOWS\reg.dat 
c:\WINDOWS\wininit.ini 
c:\WINDOWS\winstart.bat 
c:\WINDOWS\�.bat 
c:\WINDOWS\COMMAND\drvspace.bat 
c:\WINDOWS\COMMAND\msdos.sys 
c:\WINDOWS\SYSTEM\windows.dat 

MegaSecurity