Towerman 2007 D
(Trojan-Spy.Win32.Delf.uc)

by ?

Written in Delphi

Released in January 2007

Made in China

more versions

 


Server
dropped files:
c:\WINDOWS\nxempu.dll                                                           size: 131,584 bytes 
c:\WINDOWS\system32\trkwkssw.dll                                                size: 131,584 bytes
c:\WINDOWS\system32\trkwksswsw.dll                                              size: 131,584 bytes
c:\WINDOWS\system32\trkwksswswsw.dll                                            size: 131,584 bytes
c:\WINDOWS\system32\trkwksswswswsw.dll                                          size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswsw.dll                                        size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswswsw.dll                                      size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswswswsw.dll                                    size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswswswswsw.dll                                  size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswswswswswsw.dll                                size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswswswswswswsw.dll                              size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswswswswswswswsw.dll                            size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswswswswswswswswsw.dll                          size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswswswswswswswswswsw.dll                        size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswswswswswswswswswswsw.dll                      size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswswswswswswswswswswswsw.dll                    size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswswswswswswswswswswswswsw.dll                  size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswswswswswswswswswswswswswsw.dll                size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswswswswswswswswswswswswswswsw.dll              size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswswswswswswswswswswswswswswswsw.dll            size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswswswswswswswswswswswswswswswswsw.dll          size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswswswswswswswswswswswswswswswswswsw.dll        size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswswswswswswswswswswswswswswswswswswsw.dll      size: 131,584 bytes 
c:\WINDOWS\system32\trkwksswswswswswswswswswswswswswswswswswswswswswswsw.dll    size: 131,584 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\TrkWks


tested on Windows XP
March 12, 2007

MegaSecurity