Backdoor.Win32.VB.kr
(Backdoor.Win32.VB.kr)

by ?

Written in Visual Basic

more in this category


dropped files:
c:\WINDOWS\system32\Cxe0n.exe     Size: 499,798 bytes 
c:\WINDOWS\system32\Dkp0h.exe     Size: 499,712 bytes 
c:\WINDOWS\system32\Erl6AX.exe    Size: 499,798 bytes 
c:\WINDOWS\system32\FyuUb15r.exe  Size: 254,038 bytes 
c:\WINDOWS\system32\Gxzz4.exe     Size: 254,038 bytes 
c:\WINDOWS\system32\Ojz1.exe      Size: 254,038 bytes 
c:\WINDOWS\system32\PusY6.exe     Size: 254,038 bytes 
c:\WINDOWS\system32\Sdk6Lso.exe   Size: 254,038 bytes 
c:\WINDOWS\system32\Vpi2lnCV.bli  Size: 1,353 bytes 
c:\WINDOWS\system32\XdlD.exe      Size: 499,798 bytes 
c:\WINDOWS\system32\Xvh24U2.exe   Size: 254,038 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "2Q8@S9D55GY6B#"
data: C:\WINDOWS\System32\Erl6AX.exe 


tested on Windows XP
July 05, 2005

MegaSecurity