Dosh version a
(Backdoor.Win32.Dosh.a)

by ?

Written in Visual Basic

Made in China

more versions


dropped file:
C:\WINDOWS\windpd.bqi  

size: 522 KB

port: 113, 1026, 1028, 1033, 1035, 1037, 1039, 1041, 1043 TCP

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run 

keys added:
HKCR\.bqi 
HKCR\dpndfile 
HKCR\dpndfile\DefaultIcon 
HKCR\dpndfile\shell 
HKCR\dpndfile\shell\open 
HKCR\dpndfile\shell\open\command 

MegaSecurity