DWTC Iced! 2.1
(P2P-Worm.Win32.VB.dn for Server)

by Cool_mofo_2

Written in Visual Basic

Released in December 2005

more versions

 


Server:
dropped file:
c:\WINDOWS\system32\mesngr.exe
size: 53,755 bytes 

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "msn2"
data: C:\WINDOWS\System32\msn2.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "msn2"
data: C:\WINDOWS\System32\msn2.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce "msn2"
data: C:\WINDOWS\System32\msn2.exe 

tested on Windows XP
December 14, 2005

MegaSecurity