Demon-Tel Sender 1.0
(Trojan.Win32.VB.bxy)

by Masoud Azimi

Written in Visual Basic

Made in The Middle East




Server
Dropped File:
c:\WINDOWS\system32\NetCmd.exe
Size: 12,093 bytes 

Startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run "ComS"
Data: C:\WINDOWS\system32\NetCmd.exe 	
	
	
	
	
Tested on Windows XP
May 19, 2008

MegaSecurity