Newone
(Backdoor.Win32.Newon)

by ?

Written in Visual Basic

Original Filename: Sexy.exe


server



Server:
dropped files:
c:\WINDOWS\SYSTEM\systrayen.EXE   Size: 46.592 bytes 
c:\WINDOWS\SYSTEM\Dao.dat 

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "systrayen" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "systrayen" 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices 

MegaSecurity