BLACK FTP
(Trojan-Dropper.Win32.VB.mrj)

by Black Hacker

Written in Visual Basic

Released in August 2008

Made in Turkey


Server
Dropped File:
c:\WINDOWS\system32\Restore\wscntfy.exe
Size: 81,920 bytes 

Startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Activex"
Data: C:\WINDOWS\system32\Restore\wscntfy.exe 
	


Tested on Windows XP
September 10, 2008

MegaSecurity