PoeBot (b)
(Backdoor.Win32.PoeBot.b)

by ?

Written in Borland C++

more versions




dropped file:
c:\WINDOWS\system32\defragfatz.exe
size: 81,920 bytes 

port: 113 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows DLL Loader"
data: C:\WINDOWS\system32\defragfatz.exe 
	
	

tested on Windows XP
January 11, 2006

MegaSecurity