Dasmin
(Backdoor.Win32.Dasmin)

by ?


dropped files:
c:\WINDOWS\system32\AVIRCHK.EXE    Size: 61,632 bytes 
c:\WINDOWS\system32\JDBGMRG.EXE    Size: 61,632 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "MSConfigr"
data: C:\WINDOWS\System32\JDBGMRG.EXE 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "VirusCheckII"
data: C:\WINDOWS\System32\AVIRCHK.EXE 


tested on Windows XP
October 10, 2005

MegaSecurity