SharaQQ 4.1
(Trojan.PSW.SharaQQ.40)

by Just Paradise

Compressed with UPX

Made In China

Released in 2002

more versions




Server:
dropped files:
C:\WINDOWS\SYSTEM\Rundlll.exe 
C:\WINDOWS\Pal.exe 

size: 49.224 bytes

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Defaults" 
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce "Defaults" 
HKCR\txtfile\shell\open\command "(Default)" 

Added:
c:\WINDOWS\SYSTEM\config.dll 
c:\WINDOWS\SYSTEM\Iexplarer.dll 
c:\WINDOWS\SYSTEM\Rundlll.dat 

MegaSecurity