Size: 59051 bytes
Affected OS: Win95/98/NT/2k/XP/2k3
Packed by: FSG
%Windir%\System32\seppgs.dll, %Windir%\System32\zq.dll (39972 bytes, packed by UPX, are detected by Dr.Web antivirus as Backdoor.Haxdoor.320)
%Windir%\System32\twpkbd.sys, %Windir%\System32\zq.sys (21856 bytes, packed by UPolyX, are detected by Dr.Web antivirus as Backdoor.Haxdoor.320).
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\seppgm
HKLM\SYSTEM\ControlSetXXX\Control\SafeBoot\Minimal\seppgm.sys
HKLM\SYSTEM\ControlSetXXX\Control\SafeBoot\\Control\SafeBoot\Minimal\seppgm.sys
HKLM\SYSTEM\ControlSetXXX\\Control\SafeBoot\Network\seppgm.sys
HKLM\SYSTEM\ControlSetXXX\\Control\SafeBoot\Network\seppgm.sys
Service output names: "TCP x IP2 Kernel" и "TCP x IP2 Kernel32".
HKLM\SYSTEM\ControlSetXXX\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\%Windir%\Explorer.EXE: "%Windir%\Explorer.EXE:*:Enabled:explorer"
HKLM\SOFTWARE\Agnitum\Outpost Firewall
HKLM\SOFTWARE\Agnitum\Outpost Firewall\Paths
NtCreateProcess
NtCreateProcessEx
NtOpenProcess
NtOpenThread
NtQueryDirectoryFile
NtQuerySystemInformation
vp.ch
avp.com
avp.ru
awaps.net
customer.symantec.com
dispatch.mcafee.com
download.mcafee.com
downloads1.kaspersky-labs.com
downloads1.kaspersky-labs.com
downloads1.kaspersky-labs.com
downloads2.kaspersky-labs.com
downloads3.kaspersky-labs.com
downloads4.kaspersky-labs.com
downloads-us1.kaspersky-labs.com
downloads-us2.kaspersky-labs.com
downloads-us3.kaspersky-labs.com
engine.awaps.net
f-secure.com
ftp.avp.ch
ftp.downloads2.kaspersky-labs.com
ftp.f-secure.com
ftp.kasperskylab.ru
ftp.kaspersky.ru
d-ru-1f.kaspersky-labs.com
d-ru-2f.kaspersky-labs.com
d-eu-1f.kaspersky-labs.com
d-eu-2f.kaspersky-labs.com
d-us-1f.kaspersky-labs.com
ftp.sophos.com
ids.kaspersky-labs.com
kaspersky.com
kaspersky-labs.com
liveupdate.symantec.com
liveupdate.symantec.com
liveupdate.symantec.com
liveupdate.symantecliveupdate.com
liveupdate.symantecliveupdate.com
mast.mcafee.com
mcafee.com
my-etrust.com
networkassociates.com
phx.corporate-ir.net
rads.mcafee.com
securityresponse.symantec.com
service1.symantec.com
sophos.com
spd.atdmt.com
symantec.com
trendmicro.com
update.symantec.com
updates.symantec.com
updates1.kaspersky-labs.com
updates1.kaspersky-labs.com
updates2.kaspersky-labs.com
updates3.kaspersky-labs.com
updates3.kaspersky-labs.com
updates4.kaspersky-labs.com
updates5.kaspersky-labs.com
us.mcafee.com
virustotal.com
zapro.exe
vsmon.exe
jamapp.exe
atrack.exe
iamapp.exe
FwAct.exe
mpfagent.exe
outpost.exe
zlclient.exe
mpftray.exe