UpKiller's RootKit 0.55
(Backdoor.UpRootKit)

by UpKiller

Written in Visual C++

Released in December 2003

Made in China



-----------------    Upkiller's RootKit Command Help     -------------

[help]     >>>>>>>>>>>>>>>>>>>>>>>>>>>>> Get Command Help.
[Pslist]   >>>>>>>>>>>>>>>>>>>>>>>>>>>>> List All Processes.
[Pskill]   >>>>>>>>>>>>>>>>>>>>>>>>>>>>> Kill The Process With The Pid.
[Shell]    >>>>>>>>>>>>>>>>>>>>>>>>>>>>> Get Cmommand Shell.
[DDos]     >>>>>>>>>>>>>>>>>>>>>>>>>>>>> Syn Flood Dos (Tcp).
[Stopddos] >>>>>>>>>>>>>>>>>>>>>>>>>>>>> Stop DDOS Thread.
[Version]  >>>>>>>>>>>>>>>>>>>>>>>>>>>>> Display UpRootKit's Version.
[Reboot]   >>>>>>>>>>>>>>>>>>>>>>>>>>>>> Reboot The This System.
[Poweroff] >>>>>>>>>>>>>>>>>>>>>>>>>>>>> ShutDown The This System Power.
[Exit]     >>>>>>>>>>>>>>>>>>>>>>>>>>>>> Exit the Shell or UpRootKit.

Upkiller


Rootkit.exe:
dropped file:
c:\WINNT\system32\uprootkit.exe
 
size: 49.152 bytes

port: 0

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_UPROOTKIT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UpRootKit\Enum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UpRootKit\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_UPROOTKIT\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UpRootKit\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UpRootKit\Security

tested on Win2000 

MegaSecurity