Beast 2.06 (f) Server
(Backdoor.Win32.Beastdoor.206.f)

by Tataye

Written in Delphi

Made in Rumania

more versions




Server:
dropped files:
c:\WINDOWS\msagent\msqoet.com     Size: 69,758 bytes 
c:\WINDOWS\system32\mslg.blf      Size: 43 bytes 
c:\WINDOWS\system32\mssphe.com    Size: 69,758 bytes 
c:\WINDOWS\system32\winlog.exe    Size: 69,758 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{42CE4021-DE03-E3CC-EA32-40BB12E6015D} "StubPath"
data: C:\WINDOWS\System32\mssphe.com 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run "COM Service"
data: C:\WINDOWS\msagent\msqoet.com 



tested on Windows XP
March 08, 2006 

MegaSecurity