TrojanC VIP 2006
(Backdoor.Win32.Agent.zh)

by seven-eleven

Released in May 2006

Made in China

more versions





Server:
dropped files:
c:\WINNT\system32\GetPass_eph.dll    Size: 5,120 bytes 
c:\WINNT\system32\R_Server.dat       Size: 48,128 bytes 
c:\WINNT\system32\R_Server.exe       Size: 74,090 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\R_Server\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\R_Server\Security


tested on Windows 2000
May 31, 2006

MegaSecurity