Winter Love HackBase
(Backdoor.Win32.WinterLove.x)

by plunix

Written in Microsoft Visual C++

Released in June 2005

Made in China

more versions

                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 
                                    


Server:
dropped file:
c:\WINNT\system32\myDll.dll
size: 73,728 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SAM\SAM\Domains
HKEY_LOCAL_MACHINE\SAM\SAM\RXACT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MYSRVSHELL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MySrvShell
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYSRVSHELL
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MySrvShell



tested on Windows 2000
June 09, 2005

MegaSecurity