WANRemote 3.0 (b)
(Backdoor.Win32.Wanremote.30.b)

by BRAiN/Digitalis

Written in Delphi

more versions


Server:
dropped file:
c:\WINDOWS\MSHTTPD.EXE
size: 435,200 bytes 

port: 80 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "MSHTTPD.EXE"
data: C:\WINDOWS\MSHTTPD.EXE 

tested on Windows XP
January 15, 2006

MegaSecurity