SpYCQ 1.3
(Trojan-Spy.Win32.Delf.mh)

by the_seed

Written in Delphi

Released in July 2006

Made in Germany




Server:
dropped file:
c:\WINDOWS\system32\winsys.exe
size: 414,720 bytes 

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "explorer##########"
data: C:\WINDOWS\system32\winsys.exe 



tested on Windows XP
July 26, 2006

MegaSecurity