Dosh version c
(Backdoor.Win32.Dosh.c)

by ?

Written in Visual Basic

Made in China

more versions


Dropped file:
c:\WINDOWS\system32\oce32.wdep
size: 827,392 bytes 

added to registry:
HKEY_CLASSES_ROOT\.wdep "(Default)"
data: dpendfile 

HKEY_CLASSES_ROOT\dpendfile "(Default)"
data: Windows Dependent 

HKEY_CLASSES_ROOT\dpendfile\DefaultIcon "(Default)"
data: c:\windows\system\shell32.dll,-154 

HKEY_CLASSES_ROOT\dpendfile\shell\open\command "(Default)"
data: "%1" %* 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "oec"
data: c:\windows\system32\oce32.wdep 



tested on WindowsXP
February 27, 2005

MegaSecurity