Archstealer
(Backdoor.Win32.Agent.ioo)

by grzonu

Released in August 2007

Made in Poland




Dropped File:
c:\WINDOWS\kernel.exe
size: 525,974 bytes 

port: 4321 TCP

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "kernel"



tested on Windows XP
August 28, 2007

MegaSecurity