Backdoor.Win32.VB.hr
(Backdoor.Win32.VB.hr)

by ?

Written in Visual Basic

more in this category


Backdoor.Win32.VB.hr:
dropped file:
c:\WINDOWS\system\tkjem.exe
size: 61,440 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "LoadGamma"
data: c:\windows\system\tkjem.exe /BRHFN 
	
attempts to connect to an IRC Server

	
	
tested on Windows XP 
June 25, 2005

MegaSecurity