GregStar Trojan 2.4
(Backdoor.Win32.HacDef.kv)
(Backdoor.Win32.HacDef.tovd for Server)

by gregstar

Written in Delphi

Released in January 2006

more versions




Server:
dropped files:
c:\WINDOWS\runt.bat    Size: 37 bytes 
c:\WINDOWS\shell.exe   Size: 741,876 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run "winshell"
data: C:\WINDOWS\shell.exe 



tested on Windows XP
January 30, 2006

MegaSecurity