FTP99
(Backdoor.Win32.Ftp99)
(Backdoor.Win32.ServU-based for Windll16.exe)

by Hackcity

Written in Borland C++

Released in May 1999


Server:
c:\WINDOWS\SYSTEM\Windll16.exe 

size: 607.744 bytes 

port: 1492 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "WinDLL_16" 

added:
c:\Program Files\My Paquet archive\Serv-u.ini 
c:\WINDOWS\Regmak.exe 
c:\WINDOWS\SYSTEM\IPSERVU.TXT 

MegaSecurity