BitHood v2
(Backdoor.Win32.Agent.xr)

by s@S@n

Written in Delphi

Released in March 2006

Made in Poland

more versions





Server:
dropped file:
c:\WINDOWS\scxv32dll.exe
size: 737,480 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "kernell32"
data: C:\WINDOWS\scxv32dll.exe 


tested on Windows XP
April 07, 2006

MegaSecurity