RTB 666 0.96
(Backdoor.Win32.RTB.096)

by R*fl*x

Compressed with ASPack

Released in February 2001

Made in Poland

more versions


Server:
dropped file:
c:\WINDOWS\SHELLAPI.EXE
size: 138.240 bytes 
 
port: 23 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Microsoft Shell API Service"
data: C:\WINDOWS\SHELLAPI.EXE 

tested on Windows 98
November 21, 2004

MegaSecurity