DWTC Iced!
(P2P-Worm.Win32.VB.dn for Server)

by Cool_mofo_2

Written in Visual Basic

Released in November 2005

more versions

 


Server:
dropped file:
c:\WINDOWS\system32\mesngr.exe
size: 70,142 bytes 

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "msn2"
data: C:\WINDOWS\System32\msn2.exe 

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache "@shell32.dll,-31321"
data: Hide the contents of this drive 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "msn2"
data: C:\WINDOWS\System32\msn2.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce "msn2"
data: C:\WINDOWS\System32\msn2.exe 

	
	
tested on Windows XP
June 20, 2006

MegaSecurity trojans/m/mofotro/ImagesP/vdmzi8.jpg