SWZ2007 Fly
(Backdoor.Win32.Swz.yj)
(Backdoor.Win32.Swz.kg)
(Backdoor.Win32.Swz.gw)

by ?

Written in Delphi

Released in February 2007

Made in China


Server
dropped file:
c:\WINDOWS\system32\Systen.dll
size: 125,440 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BITS
HKEY_LOCAL_MACHINE\SOFTWARE\Tencent\QQ "Tencent"


tested on Windows XP
February 15, 2007

MegaSecurity