Backdoor.Win32.VB.hg
(Backdoor.Win32.VB.hg)

by ?

Written in Visual Basic, compressed with UPX

more in this category


Backdoor.Win32.VB.hg:
dropped file:
c:\WINDOWS\system32\SystemTray.exe
size: 30,208 bytes 

port: 2707 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices "SystemTray"
data: C:\WINDOWS\System32\SystemTray.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit "SystemTray"
data: C:\WINDOWS\System32\SystemTray.exe 




tested on Windows XP 
June 15, 2005

MegaSecurity