Azrael2P 2.0
(Trojan.Win32.Soul.b)
(not-a-virus:RemoteAdmin.Win32.Azrael.c)

by x_uy_u_n

Compressed with UPX

Released in September 2004

Made in China

more versions


Server:
dropped files:
c:\WINNT\system32\soul.dll     size: 76.288 bytes 
c:\WINNT\system32\spoo1sv.exe  size: 91.648 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SOULSERVICE\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SoulService\Enum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SoulService\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOULSERVICE\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SoulService\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SoulService\Security

tested on Win2000

MegaSecurity