Optix Lite


Name: Optix Lite
Aliases: Backdoor.Optix, Troj_Optix, Backdoor.RS, BDS.Optix, Win32.Optix, Backdoor.AHE,
Ports: 80, 5151, 27379 (ports can be changed)
Files: Optixlite.zip - 301.390 bytes Optixlite0.1.zip - 281,359 bytes Optixlite0.2.zip - 301,452 bytes Optixlitegw-server0.2.zip - 36,283 bytes Optixlite0.3.zip - 347,877 bytes Optixlite0.4.zip - 383,505 bytes Optixlite2.zip - Cgi-logger.zip - 21,814 bytes Cgi-logger.zip - 24,224 bytes Optixgw.zip - 35,894 bytes Optixgw0.2.zip - 35,894 bytes Olfwb.zip - 440,851 bytes Client.exe - 262,144 bytes Client.exe - 274,432 bytes Client.exe - 285,184 bytes Client.exe - 306,688 bytes Server.exe - 66,560 bytes Server.exe - 75,776 bytes Server.exe - 80,384 bytes Server.exe - 80,386 bytes Server.exe - 82,432 bytes Server.exe - 222,720 bytes Optixclient.exe - 245,248 bytes Optixgwserver.exe - Optixglitewserver.exe - 66,560 bytes Winsmtp.plg - 82,944 bytes Winx.exe - Winxp.exe - Winsswr.exe - Subseven.cgi - Tapisvc.sys - Setup.int - 0943263.exe - Infector_6dec.exe - Pserver1dec.exe - Win32svc.exe - Regscanr.exe - Plugin32.dll - Yahoo updater.com - - 28,674 bytes - 39,424 bytes - 67,584 bytes - 287,744 bytes - 400,975 bytes
Created: Jul 2001
Requires:
Actions: Anti-protection trojan / Remote Access / Keylogger / SMTP server / Downloading trojan / Destructive trojan
Registers: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components
HKEY_LOCAL_MACHINE\Software\
Notes: Works on Windows 95, 98, ME, NT, 2000 and XP.
Country:
Program: Written in Borland Delphi 5.0.

© Copyright von Braun Consultants. This information may include technical inaccuracies or typographical errors. If you have any questions or further information about the actual trojan above, please contact Joakim von Braun at <joakim.von.braun@risab.se>