Mybr 1.0
(Trojan.Win32.Slefdel.ape)
(Trojan-Dropper.Win32.Delf.acu for Server)

by ?

Written in Delphi

Released in February 2007

Made in China

more versions


Server
dropped files:
c:\WINDOWS\system32\pzh.dat       Size: 368 bytes 
c:\WINDOWS\system32\system.dll    Size: 317,952 bytes 
c:\WINDOWS\system32\system.exe    Size: 415,744 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SYSTEM\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\system
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYSTEM\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\system


tested on Windows XP
March 17, 2007

MegaSecurity