Byshell 1.09
(Backdoor.Win32.Agent.atq)
(Backdoor.Win32.Agent.atr for Server)

by ?

Released in August 2007

Made in China

more versions

 



Server
added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NTBOOT32\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NTboot\Security
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\te
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\C
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NTBOOT32\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTboot\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\te

Deleted files:
c:\NTDETECT.COM
c:\Documents and Settings\Default User\NTUSER.DAT
c:\Documents and Settings\Default User\NTUSER.DAT.LOG
c:\Documents and Settings\%user%\NTUSER.DAT
c:\Documents and Settings\%user%\NTUSER.DAT.LOG
c:\Documents and Settings\LocalService\NTUSER.DAT
c:\Documents and Settings\NetworkService\NTUSER.DAT 
c:\WINDOWS\system32\dllcache\NT5.CAT
c:\WINDOWS\system32\dllcache\NT5IIS.CAT
c:\WINDOWS\system32\dllcache\NT5INF.CAT
c:\WINDOWS\system32\dllcache\NTPRINT.CAT 



tested on Windows XP
August 30, 2007

MegaSecurity