CFour
(Backdoor.Win32.CFour)

by ?

Made in Visual Basic


Dropped file:
C:\WINDOWS\SYSTEM\C4.EXE 

size: 104 KB

startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run "Gpkvlhqwj" 
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Hdhwpdpzyt" 
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices "Efzpgin" 
HKCU\Software\Mirabilis\ICQ\Agent\Apps

MegaSecurity