Created: OCT 1999
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
HKU\.Default\Software\Microsoft\Windows\CurrentVersion\Run\
Posts Tagged ‘HKU’
Chupacabra
Bugs
Aliases: Backdoor.Win32.Feap
Port: 2115
Size: 76kb
Author: Wedson
Created: TBD
OS:
Bobo
Aliases: “Bo-Bo” – Backdoor.Napalm.a
Variants: 1.0, 1.0b
Port: 4321
Size: 321kb
Author: Napalm
Created: JUN 1999
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
HKU\.Default\Software\Mirabilis\ICQ\Agent\Apps\ICQ Accel\
Infection: dllclient.exe, bobo.exe
BitchController
Aliases: Backdoor.Win32.Bitcon.205
Variants: 2.05
Port: 13010
Size: 92kb
Created: TBD
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\
Infection: the bitch controller.exe
Backage
Aliases: Backdoor.Backage.30, Backdoor.Backage.301, Backdoor.Backage.31, Backdoor.Backage.31.b, Backdoor.Backage.31.c, Backdoor.Backage.32
Variants: 3.0, 3.01, 3.1, 3.1.1, 3.2 SE
Port: 5333
Size: 97kb
Author: Ne-O-Sk8
Created: JUL 2000
OS: Windows
Location:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunService\
HKU\.Default\Software\Microsoft\Windows\CurrentVersion\Run\
HKU\.Default\Software\Microsoft\Windows\CurrentVersion\RunOnce\
HKU\.Default\Software\Win\Run\
Infection: systemkernel32, winstop32.exe, backage 3.2 se.exe, backage3.ini, backage32se.backage, backageclient.exe, backageserver.exe, backdoor.backage.31.b.exe, desintall.exe, edit server.exe, help.txt, makeskinz.exe, readme(skin).txt, readme.txt, readme_english.txt, skin.ini, mskernel16.exe



