by plunix
Written in Microsoft Visual C++
Released in June 2005
Made in China

Server:
dropped file:
c:\WINNT\system32\server.dll
size: 70,656 bytes
port: 3043 TCP
added to registry:
HKEY_LOCAL_MACHINE\SAM\SAM\Domains
HKEY_LOCAL_MACHINE\SAM\SAM\RXACT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MYSRVSHELL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MySrvShell
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYSRVSHELL
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MySrvShell
tested on Windows XP
July 15, 2005
MegaSecurity