SNaP D00R 0.85
(Backdoor.Win32.VB.akz)

by SNaP TEAM

Written in Visual Basic

Released in June 2005

more versions


Server:
dropped files:
c:\WINDOWS\MNETCONEC.COM        Size: 1,388,544 bytes 
c:\WINDOWS\MSLG.DLL             Size: 24 bytes 
c:\WINDOWS\system32\MSLG.DLL    Size: 24 bytes 
c:\Documents and Settings\%user%\Local Settings\Temp\PASSWORDS (Numeracions).DOC .doc

port: 23 TCP

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "MicrosoftUpdater"
data: C:\WINDOWS\MNETCONEC.COM 
	
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run "MicrosoftUpdater"
data: C:\WINDOWS\MNETCONEC.COM 

HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run "MicrosoftUpdater"
data: C:\WINDOWS\MNETCONEC.COM 	

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell"
old data: Explorer.exe 
new data: Explorer.exe MNETCONEC.COM 


tested on Windows XP
September 25, 2005

MegaSecurity