Phoenix2 1.72
(Backdoor.Win32.Phoenix.172)

by C)DMP & Kaosł

Written in Microsoft Visual C++

Released in October 2001

Made in Italy

more versions


Server:
dropped files:
c:\WINDOWS\Msatrib.EXE   size: 217.088 bytes 
c:\WINDOWS\TEMP\~P2.EXE  size: 217.088 bytes 

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Msatrib"
data: C:\WINDOWS\Msatrib.EXE 

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce "C:\WINDOWS\TEMP\~P2.EXE"
data: C:\WINDOWS\Msatrib.exe /del C:\WINDOWS\TEMP\~P2.EXE 
	
tested on Windows 98
November 18, 2004

MegaSecurity