Nightingale 2.9
(Not detected by KAV on August 13, 2007)

by Yeying


Released in August 2007

Made in China

more versions




Server
dropped file:
c:\WINDOWS\system32\YYServer.exe
size: 331,407 bytes 

added to registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\WinOldApp
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_YYSVC\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\YYSvc\Enum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\YYSvc\Security
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_YYSVC\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\YYSvc\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\YYSvc\Security



tested on Windows XP
August 13, 2007

MegaSecurity