Backdoor.Win32.VB.ih
(Backdoor.Win32.VB.ih)

by AMDLA

Original Filename: diomedes.exe

Written in Visual Basic

Released in October 2001

Probably made in Spain

more in this category


dropped files:
c:\WINDOWS\system32\winodbc.exe    Size: 147,456 bytes 
c:\WINDOWS\system32\winodbc.sys    Size: 147,456 bytes 

port: 22179, 22180, 22181
startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "SPcntrl"
data: C:\WINDOWS\System32\winodbc.exe 

tested on Windows XP
August 23, 2005

MegaSecurity