R8myp00 IrcBot 1.0
(Backdoor.Win32.Rybot.a)
(Backdoor.Win32.Rybot.b)

by ShapeLeSS

Released in March 2004


Server:
dropped files:
c:\WINDOWS\SYSTEM\msdn.exe      Size: 65.536 bytes 
c:\WINDOWS\SYSTEM\msdn.exe 
c:\WINDOWS\SYSTEM\rplib.dll 
c:\WINDOWS\SYSTEM\rtm.dat

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "MSDN" 

MegaSecurity