Remote CowRat
(Trojan-Spy.Win32.Delf.fpu)

by Kaju

Written in Delphi

Released in October 2008




Server
Dropped Files:
c:\WINDOWS\system\services.exe
Size: 640,000 bytes 

Startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Adobe Reader Speed Launchers"
Data: C:\WINDOWS\system\services.exe 
		
	

Tested on Windows XP
October 10, 2008

MegaSecurity