Indoctrination
(Backdoor.Win32.Progenic.20.c)
(Backdoor.Win32.Progenic.20 for Server)

by Progenic Warfare

Compressed with ASPack

Released in May 1999


Server:
dropped file:
C:\WINDOWS\SYSTEM\MSGSRV16.EXE

size: 29.184 bytes

port: 6939 TCP

startup:
HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNSERVICES
HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN
HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE
HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNSERVICESONCE
HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN

MegaSecurity