Black QQ Robber 3.0 Build0203

Released 17 years, 10 months ago. January 2007

Copyright © MegaSecurity

By ?


Black QQ Robber 3.0 Build0203
Informations
From China
Author ?
Family Black QQ Robber
Category Webdownloader
Version Black QQ Robber 3.0 Build0203
Released Date Jan 2007, 17 years, 10 months ago.
Language Delphi
Additional Information
Server:
dropped files:
c:\WINDOWS\system32\dddrkn.dll            Size: 37,888 bytes 
c:\WINDOWS\system32\dddrkn.exe            Size: 31,943 bytes 
c:\WINDOWS\system32\severe.exe            Size: 31,943 bytes 
c:\WINDOWS\system32\drivers\ahwxvj.com    Size: 31,943 bytes 
c:\WINDOWS\system32\drivers\etc\hosts

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "ahwxvj"
data: C:\WINDOWS\System32\dddrkn.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell"
old data: Explorer.exe 
new data: Explorer.exe C:\WINDOWS\System32\severe.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services



tested on Windows XP
February 08, 2007

If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.