Green Light 1.0
(Backdoor.Win32.Agent.zz)
(Backdoor.Win32.Agent.ann)

by ?

Released in May 2006

Made in China

more versions

 


Server:
dropped file:
c:\WINNT\svcehost.exe
size: 265,088 bytes 

port: 38439 UDP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "svcehostsys"
data: C:\WINNT\svcehost.exe 



tested on Windows 2000
May 28, 2006

MegaSecurity