SUP
(Backdoor.Win32.VB.agn)

by Sandrinecartel

Written in Visual Basic, compressed with UPX

Made in France


Server:
dropped files:
c:\webcam.ocx                      Size: 26,624 bytes 
c:\WINDOWS\system32\ijl11.dll      Size: 180,224 bytes 
c:\WINDOWS\system32\WinDown.exe    Size: 524,288 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "KeyMouse "
data: C:\WINDOWS\system32\WinDown.exe

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows "run"
data: C:\WINDOWS\system32\WinDown.exe



tested on Windows XP
January 06, 2007

MegaSecurity