FinalFantasy 1.05
(Trojan-Downloader.Win32.Adload.dwn)
(Backdoor.Win32.Hupigon.drek)

by Amoeba

Released in September 2008

Made in China

more versions


Server
Dropped File:
c:\WINDOWS\F_Server.exe
Size: 711,680 bytes    

Added to Registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FinalFantasy_Service "ImagePath"
Data: C:\WINDOWS\F_Server.exe 
	
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FinalFantasy_Service "ImagePath"
Data: C:\WINDOWS\F_Server.exe 






Tested on Windows XP
October 20, 2008

MegaSecurity