Yungs (b)
(Backdoor.Win32.Yungs.b)

by ?

Compressed with UPX


dropped files:
c:\WINDOWS\system32\mgmthell.exe    Size: 9,728 bytes 
c:\WINDOWS\system32\RUNDEXEC.DLL    Size: 20,480 bytes 

added to registry:
HKEY_CLASSES_ROOT\CLSID\{3B9D4E31-6283-40A9-A52F-5DBD16681B51}\InProcServer32 "(Default)"
data: C:\WINDOWS\System32\RUNDEXEC.DLL 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad "Network.ConnectionCache"
data: {3B9D4E31-6283-40A9-A52F-5DBD16681B51} 




tested on Windows XP
July 08, 2005

MegaSecurity