Backdoor.Win32.VB.lf
(Backdoor.Win32.VB.lf)

by ?

Written in Visual Basic

Probably made in China

more in this category


dropped files:
c:\WINDOWS\system32\intneter.exe    Size: 27,648 bytes 
c:\WINDOWS\system32\msxplor.exe     Size: 27,648 bytes 
c:\WINDOWS\system32\systrect.exe    Size: 27,648 bytes 

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows "msxplor"
data: C:\WINDOWS\system32\msxplor.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "intneter"
data: C:\WINDOWS\system32\intneter.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "systrect"
data: C:\WINDOWS\system32\systrect.exe 




tested on Win XP
July 16, 2005

MegaSecurity