Backdoor.Win32.VB.ar
(Backdoor.Win32.VB.ar)

by Fenrir

Original Filename: vr.exe

Written in Visual Basic

Made in Germany

more in this category


dropped file:
c:\WINDOWS\WinOldAp.exe
size: 34.819 bytes
 
port: 1337, 361 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WinOldAp"
data: c:\windows\WinOldAp.exe

tested on Windows XP 

MegaSecurity