GMPB 1.13
(Backdoor.Win32.VB.mz)

by ?

Written in Visual Basic

Released in November 2003

Made in China


dropped files:
c:\WINNT\system\Mswint.dll      Size: 0 bytes 
c:\WINNT\system\Ntrdl.dll       size: 13.992 bytes 
c:\WINNT\system\Ntrdw.dll       size: 0 bytes 
c:\WINNT\system\SysTrays.exe    size: 34.816 bytes 
c:\WINNT\system32\SysTrays.exe  size: 34.816 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "SystemTrays"
data: SysTrays.exe 

tested on Win2000

MegaSecurity