Domestos 1.0
(Trojan-PSW.Win32.Coced.238.a)

by

Written in Microsoft Visual C++, compressed with ASPack

Released in September 2000

Made in Russia


Editor:
dropped file:
c:\WINDOWS\win.exe
size: 13,592 bytes 

startup:
HKEY_CURRENT_USER\Software\Mirabilis\ICQ\Agent\Apps\Run "Path"
data: C:\WINDOWS\win.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "TaskMoniitor"
data: C:\WINDOWS\win.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WOW\boot "Explorer"
data: Explorer C:\WINDOWS\win.exe 

HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows "run"
data: C:\WINDOWS\win.exe 



tested on Windows XP
February 07, 2005

MegaSecurity