TrojanMule
(Backdoor.Win32.VB.ml)

by Nerdware inc.

Written in Visual Basic

Released in February 2002




Server:
dropped file:
c:\WINDOWS\wreg.exe 

size: 41.051 bytes 

Startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "WREG" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices "WREG" 


Connects to specified IRC server and joins a channel to listen for commands 

MegaSecurity