QAzrael 1.2
(Backdoor.Win32.Small.ba)

by x_uy_u_n

Server compressed with UPX

Released in March 2004

Made in China


Server:
dropped files:
c:\WINNT\system32\soul.dll    size: 71.680 bytes 
c:\WINNT\system32\spoo1sv.exe size: 90.624 bytes 

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "spoo1sv"
data: spoo1sv.exe
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "spoo1sv"
data: spoo1sv.exe 

tested on Windows 2000

MegaSecurity