Backdoor.Win32.VB.cm
(Backdoor.Win32.VB.cm)

by ?

Original name unknown

Written in Visual Basic

more in this category


Backdoor.Win32.VB.cm:
dropped files:
c:\WINDOWS\syspuck.ini    Size: 296 bytes 
c:\WINDOWS\wcript.exe     Size: 114,688 bytes 

attempts to connect to an IRC server

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WindowsUpdate"
data: script.exe 




tested on Windows XP
May 29, 2005

MegaSecurity