Theef 1.2
(Backdoor.Win32.Theef.12)

by tt

more versions


Server:
dropped file:
C:\WINDOWS\SYSTEM\ocxreg.exe 

size: 1303 KB

port: 1000, 1001, 1005 TCP

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run 

MegaSecurity