FireFly 2.3Beta3
(Backdoor.Win32.FireFly.a)

by wsdgs

Written in Delphi

Released in December 2005

Made in China

more versions


Server:
dropped files:
c:\Program Files\FireFly\FireFlyInfo.ini    Size: 87 bytes 
c:\Program Files\FireFly\Serpent.Exe        Size: 10,861 bytes 
c:\Program Files\FireFly\WinDeBug.exe       Size: 15,445 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_FIREFLY\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FireFly
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\C
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FIREFLY
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FireFly



tested on Windows XP
December 17, 2005

MegaSecurity