B Xone 1.8 final
(Trojan.Win32.Agent.adw)

by opium

Written in Delphi, source included

Released in February 2007

Made in Russia

more versions


Server:
port: 2006 TCP

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run "svchost"
data: C:\WINDOWS\System32\Drivers\svchost.exe 

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List "C:\WINDOWS\System32\Drivers\svchost.exe"
data: C:\WINDOWS\System32\Drivers\svchost.exe:*:Enabled:svchost 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List "C:\WINDOWS\System32\Drivers\svchost.exe"
data: C:\WINDOWS\System32\Drivers\svchost.exe:*:Enabled:svchost 




tested on Windows XP
February 06, 2007

MegaSecurity