DarkSky 2.6 (a)
(Backdoor.Win32.DarkSky.26.a)

by Darksky

Written in Visual C++

Released in September 2002

Made in China

more versions


Server
Dropped Files:
c:\WINDOWS\SYSTEM\KNREL32.exe 
c:\WINDOWS\SYSTEM\notepade.exe 
c:\WINDOWS\SYSTEM\SysArchive.exe 

size: 20.480 bytes

port: 5418, 5419 TCP

startup:
HKEY_CLASSES_ROOT\.txt\shell\open\command "(Default)" 
HKEY_CLASSES_ROOT\txtfile.txt\shell\open\command "(Default)" 
HKEY_CLASSES_ROOT\txtfile\shell\open\command "(Default)" 
HKEY_CLASSES_ROOT\exefile\shell\open\command "(Default)" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices "SysArchive" 

MegaSecurity