GoToShell
(Not detected by KAV on September 20, 2007)

by Lidloses_Auge

Written in FreeBasic

Released in September 2007

Made in Germany


Server:
Dropped Files:
c:\Documents and Settings\Kobayashi\ncftp\firewall.txt
c:\WINDOWS\ncftpget.exe    Size: 172,032 bytes 
c:\WINDOWS\ncftpput.exe    Size: 167,936 bytes 
c:\WINDOWS\server.exe      Size: 381,440 bytes 
c:\WINDOWS\syschck.txt
c:\WINDOWS\cmdleer\commands1.txt

Added to Registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "server"
Data: C:\WINDOWS\server.exe 


Tested on Windows XP
September 20, 2007

MegaSecurity