MyParty


Name: MyParty
Aliases: W32.Myparty@mm, Backdoor.Myparty, I-Worm.Myparty, BackDoor.AAF, Msstake, BackDoor-FB, Win32.HLLM.MyParty, Troj/Msstake-A,
Ports:
Files: Myparty.exe - 29,696 bytes Regctrl.exe - Msstask.exe - - 6,144 bytes (UPX compressed, 152,064 bytes uncompressed) - 28,160 bytes
Created: Jan 2002
Requires:
Actions: Worm / Remote Access / SMTP server / Trojan dropper / Downloading trojan
Registers: HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts\00000001HKEY_CURRENT_USER\Software\Microsoft\WAB\WAB4
HKEY_CURRENT_USER\IDENTITIES\%X%\Software\Microsoft\Outlook Express\5.0
Notes: Works on Windows 95, 98, ME, NT, 2000 and XP, together with MS Outlook Express. The mail address used is napster@gala.net and the URL is 209.151.250.170.
Country: written in Russia
Program: Written in Visual C++.

© Copyright von Braun Consultants. This information may include technical inaccuracies or typographical errors. If you have any questions or further information about the actual trojan above, please contact Joakim von Braun at <joakim.von.braun@risab.se>