PROHOK 1.0
(Backdoor.Win32.Prohok)
(Trojan-Notifier.Win32.Delf.n)
(Backdoor.Win32.Stark.a for Server)

by Neil & ZeroCool
modified by ?

Written in Delphi

Based on Source of Smart-Hack Uploader

Released in July 2006


Server:
dropped file:
c:\WINDOWS\Kernel32.dlI
size: 300,616 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Kernel32"
data: Kernel32.dlI 

HKEY_CLASSES_ROOT\dlifile\shell\open\command



tested on Windows XP
November 15, 2006

MegaSecurity