Protoss 1.5
(Backdoor.Win32.Zerg.15)

by Shanghai Kid / SeekInRain

Client written in Visual C++

Server written in Visual Basic

Released in March 2001

Made in China

more versions


Server:
C:\WINDOWS\mstask32.exe 

size: 60 KB

port: 1115, 2060, 12321, 2001 TCP
      12321 UDP          

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices 

added:
HKLM\Software\Microsoft\Windows\CurrentVersion "Signed" 
Type: REG_SZ 
Data: c:\windows\mstask32.exe 

MegaSecurity