Nightingale 2.7
(Trojan.Win32.Delf.ibp)
(Backdoor.Win32.Hupigon.xi for Server)

by Yeying


Released in May 2007

Made in China

more versions




Server
dropped file:
c:\WINDOWS\system32\YYServer.exe
size: 332,430 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\YYSvc "ImagePath"
data: C:\WINDOWS\System32\YYServer.exe -Service 
	
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\YYSvc "ImagePath"
data: C:\WINDOWS\System32\YYServer.exe -Service 



tested on Windows XP
August 13, 2007

MegaSecurity