OICQsearch 1.65
(Backdoor.Win32.OICQSearch.165)

by ?

Written in Delphi

Released in October 2002

Made in China

more versions


client


server


Server:
c:\WINDOWS\SYSTEM\INTERNAT.EXE 
c:\WINDOWS\SYSTEM\scanregw.exe

size: 168.968  bytes

port: 2001, 2004, 2005, 2007, 2008, 2009, 2010, 2011, 2012  TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "internat.exe" 

added:
c:\WINDOWS\SYSTEM\SHELLEXT\Internet.exe (28.672 bytes) 
c:\WINDOWS\SYSTEM\VMM32\Setup\pedset.exe (57.344 bytes) 
c:\WINDOWS\TEMP\s_temp.jpg 
c:\WINDOWS\NOTEPAD.EXE (168.968 bytes) 
c:\WINDOWS\SYSTEM\INTERNAT.EXE (168.968 bytes) 
c:\WINDOWS\SYSTEM\scanregw.exe (168.968 bytes) 

MegaSecurity