Serman (a)
(Backdoor.Win32.Serman.a)

by Jordanov

Written in Microsoft Visual C++

SOCKS4 version 4A server (beta)





dropped file:
c:\WINDOWS\system32\wwm.exe
size: 9,248 bytes 

port: 21422 TCP

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Multimedia"

Usage: socks4 <LocalPort> [LogFile]



tested on Windows XP
May 05, 2005

MegaSecurity