Backdoor.Win32.VB.zz
(Backdoor.Win32.VB.zz)

by InGOOD CRACKING GROUP

Original Filename: thecrack.exe

Written in Visual Basic

Released in November 2004

Probably made in Germany

more in this category


Backdoor.Win32.VB.zz:
dropped file:
c:\WINDOWS\svchost.exe
size: 901,120 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "RPC Locator"
data: C:\WINDOWS\svchost.exe hide 




tested on Windows XP
July 01, 2005

MegaSecurity