NETrojan 1.0
(Backdoor.Win32.Netrojan)

by ThundeR GoD

Released in September 1999

Made in Brazil


Message Box by Server


Server:
dropped files:
c:\WINDOWS\fxp.exe               Size: 251.392 bytes 
c:\WINDOWS\PIF\command.PIF       Size: 967 bytes 
c:\WINDOWS\SYSTEM\glide16.exe    Size: 251.392 bytes 
c:\WINDOWS\SYSTEM\redire32.exe   Size: 31.744 bytes 
c:\WINDOWS\SYSTEM\rg32.exe       Size: 122.880 bytes 

replaced files:
c:\WINDOWS\REGEDIT.EXE
old size: 122.880 bytes 
new size: 135.680 bytes 



startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Regi "
data: C:\WINDOWS\SYSTEM\glide16.exe 

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices "Windlg"
data: C:\WINDOWS\SYSTEM\glide16.exe 

c:\windows\win.ini, [windows] "run"
old value: 
new value: C:\WINDOWS\fxp.exe 



tested on Windows 98
June 06, 2005

MegaSecurity