Net-Devil 1.1 (c) Server
(Backdoor.Win32.NetDevil.11.c)

by Nilez

Written in Delphi

more versions


Server:
dropped file:
c:\WINDOWS\SYSTEM\SHELLAPI.EXE
size: 602.112 bytes 

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices "ShellApi"
data: C:\WINDOWS\SYSTEM\SHELLAPI.EXE 



tested on Windows 98
December 21, 2005

MegaSecurity