OICQsearch 1.5
(Backdoor.Win32.OICQSearch.15)

by ?

Written in Delphi

Released in July 2001

Made in China

more versions


Client:
port: 401, 402 TCP



Server:
dropped files:
c:\WINDOWS\SYSTEM\scanregw.exe 
c:\WINDOWS\SYSTEM\taskmon.dep 

size: 358.912 bytes

port: 102, 2648 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "TaskMonitor" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "ScanRegistry" 

MegaSecurity