Parasite
(Backdoor.Win32.Parasite)

by ?

Compressed with NeoLite

Released in January 2001


Server:
dropped files:
C:\WINDOWS\SHELL.EXE
C:\WINDOWS\SYSTEM\SHELL.EXE
c:\WINDOWS\Parasite.exe 
c:\WINDOWS\shell.exe 
c:\WINDOWS\system.rbm 
c:\WINDOWS\SYSTEM\shell.exe

port: 64275, 19116 TCP

added to registry::
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows Shell" 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices "Windows Shell" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Scandick" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices "Windows Shell" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Buttsex2000 
HKEY_LOCAL_MACHINE\Software\RBM 
HKEY_LOCAL_MACHINE\Software\RBM\Parasite 
system.ini

MegaSecurity