CommInet (p)
(Backdoor.Win32.CommInet.p)

by ?

Compressed with UPX

more versions




dropped file:
c:\WINDOWS\hostdll.exe
size: 13,828 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "hostdll.exe"
data: C:\WINDOWS\hostdll.exe 

MD5: 1532c7bf7f71c4fc314f5a4df098eb68

attempts to connect to an IP located in Argentina

the text string "INETCOMM Server Passwords" can be found in the executable



tested on Windows XP
May 03, 2005

MegaSecurity