Hackerz Backdoor 3.7 server v2
(Backdoor.Win32.VB.qo)

by Zinyth

Written in Visual Basic, compressed with UPX


Made in France

more versions


Server:
dropped file:
c:\WINDOWS\csrss.exe
size: 129.024 bytes 

c:\Documents and Settings\%user%\Local Settings\Temp\27007.exe
size: 196.608 bytes

port: 8080, 8081 TCP

startup;
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Olepro32.dll"
data: C:\WINDOWS\csrss.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\runservicesonce "Olepro32.dll"
data: C:\WINDOWS\csrss.exe 


tested on Windows XP
December 18, 2004

MegaSecurity