Blind Downloader 1.1
(TrojanDownloader.Win32.VB.ev)

by FeraliX

Written in Visual Basic

Released in August 2004


Notes
URL: Enter The URL of the file you want to be downloaded.
Downloader Name: After Downloading, It will rename the file to whatever you chose.
Registry Name: Value Name of the Registry String.
Melt Server: It will delete the file you sent them after they execute it.
Pack With UPX: Reduce's the file size.
Error Message: Once they execute the file, It will display a fake error message.

FeraliX
 

dropped file:
c:\WINNT\system32\mswinsock.exe

size: 17.527 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Winsock Loader"
data: C:\WINNT\system32\mswinsock.exe 

tested on Win2000

MegaSecurity