Bregol
(Backdoor.Win32.Bregol)

by ?

Written in Visual Basic




dropped files:
c:\keyl_install.log            size: 14 bytes 
c:\WINDOWS\SYSTEM\.exe         size: 95.744 bytes 
c:\WINDOWS\SYSTEM\Keyinfo.txt  size: 12 bytes 
c:\WINDOWS\SYSTEM\Keylog.txt   size: 0 bytes 
c:\WINDOWS\SYSTEM\sqldbedt.exe size: 95.744 bytes 

added to registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "MSMSGS"
data: 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Yahoo! Pager"
data: 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "MSMSGS"
data: 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "sqldbedt"
data: C:\WINDOWS\SYSTEM\sqldbedt.exe 

internal name:
Greeting_summer200_1_Flash5

original file name:
Greeting_summer200_1_Flash5.exe

MegaSecurity