Buschtrommel 1.21
(Backdoor.Win32.Bushtrommel.12)

by Natok

Written in Delphi

Made in Germany

more versions


Buschtrommel can disable:
Sphinx
Conseal
Lockdown 2k
McAfee
AVP


Server:
dropped file:
C:\WINDOWS\system32\system.exe 

size: 228 KB

port: 31745 TCP

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices  

MegaSecurity