NokNok 6.0
(Backdoor.Win32.Noknok.60)

by V.P

Written in Delphi

Made in Lithuania

more versions


Server:
dropped file:
c:\abcdef             size: 2.166 bytes 
c:\abcdefgh           size: 50 bytes 
c:\WINDOWS\SETUP.EXE  size: 705.024 bytes 
 
port: 666, 667, 668 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "rundll"
data: C:\WINDOWS\setup.exe 

tested on Windows 98
08 November 2004

MegaSecurity