Hzdoor (a)
(Backdoor.Win32.Hzdoor.a)

by ?

Written in Microsoft Visual C++


dropped files:
c:\Documents and Settings\%user%\Desktop\ccSetMngr.exe  (Exploit.Win32.MS04-045.a)
size: 45,056 bytes 

c:\WINDOWS\system32\ccEvtMngr.exe
size: 139,264 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "nortonsantivirus"
data: C:\WINDOWS\System32\ccEvtMngr.exe 



tested on Windows XP
May 09, 2005

MegaSecurity