RamBooster (a)
(Backdoor.Win32.BoomRaster.a)

by ?

Released in September 2004



Backdoor.Win32.BoomRaster.a:
dropped file:
c:\WINNT\system32\rb.exe

size: 8.704 bytes
 
port: 4321, 5555, 1052 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "RamBooster2"
data: C:\WINNT\system32\rb.exe
 
tested on Win2000

MegaSecurity