Over-Ride 1.2
(Backdoor.Win32.VB.agu)

by NabZ &Evil_inside

Written in Visual Basic

Released in August 2005


Server:
dropped files:
c:\WINDOWS\system\iexplorer32.exe       Size: 434,620 bytes 
c:\WINDOWS\system32\iexploreri32.exe    Size: 434,620 bytes 

port: 45567 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Start"
data: c:\windows\system\iexplorer32.exe 




tested on Windows XP
August 08, 2005

MegaSecurity