Skydance 2.29
(Backdoor.Win32.SkyDance.229)

by Edrin

Written in Microsoft Visual C++

Released in August 2000

Made in Germany

more versions





Client:
added to registry:
HKEY_CLASSES_ROOT\.sky "(Default)"
data: NewCon.Document 

HKEY_CLASSES_ROOT\.sky\ShellNew "NullFile"

HKEY_CLASSES_ROOT\NewCon.Document "(Default)"
data: NewCon Document 

HKEY_CLASSES_ROOT\NewCon.Document\DefaultIcon "(Default)"
sata: C:\WINDOWS\DESKTOP\SKYDAN~1.25B\SKYDAN~1.EXE,1 

HKEY_CLASSES_ROOT\NewCon.Document\shell\open\command "(Default)"
data: C:\WINDOWS\DESKTOP\SKYDAN~1.25B\SKYDAN~1.EXE "%1" 

HKEY_CLASSES_ROOT\NewCon.Document\shell\print\command "(Default)"
data: C:\WINDOWS\DESKTOP\SKYDAN~1.25B\SKYDAN~1.EXE /p "%1" 

HKEY_CLASSES_ROOT\NewCon.Document\shell\printto\command "(Default)"
data: C:\WINDOWS\DESKTOP\SKYDAN~1.25B\SKYDAN~1.EXE /pt "%1" "%2" "%3" "%4" 





Server:
dropped file:
c:\WINDOWS\Skd.exe
size: 188.416 bytes 

port: 4000 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Skd"
data: C:\WINDOWS\Skd.exe 



tested on Windows 98
November 22, 2004

MegaSecurity