Towerman 2007 G
(Trojan-Spy.Win32.Delf.uc)
(Backdoor.Win32.Swz.go)

by ?

Written in Delphi

Released in February 2007

Made in China

more versions

 


Server
dropped files:
c:\WINDOWS\285.dat                Size: 15,360 bytes 
c:\WINDOWS\system32\Systen.dll    Size: 148,992 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\TrkWks
HKEY_LOCAL_MACHINE\SOFTWARE\Tencent\QQ "Tencent"



tested on Windows XP
March 16, 2007

MegaSecurity