Wisdom (c)
(Backdoor.Win32.Wisdoor.c)

by ?

Written in C++, compressed with UPX, source included

more versions




dropped files:
c:\WINDOWS\RUNDLL16.EXE  Size: 37,888 bytes 
c:\WINDOWS\temp.bat      Size: 92 bytes      (Trojan.BAT.Zapchast)

port: 559 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows DLL Loader"
data: C:\WINDOWS\RUNDLL16.EXE 



tested on Windows XP
January 27, 2005

MegaSecurity