EYE SPY
(Trojan-Spy.Win32.VB.dd)

by Splinter

Written in Visual Basic

Released in September 2004




Server:
dropped files:
c:\WINDOWS\msnmsgr.exe         size: 34.668 bytes 
c:\WINDOWS\SYSTEM\Updates.exe  size: 34.668 bytes 

port: 907 TCP

added to registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "MSN Messenger Service"
data: c:\windows\msnmsgr.exe
 
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Windows Updates"
data: c:\windows\Updates.exe
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "MSN Messenger Service"
data: c:\windows\msnmsgr.exe
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Updates"
data: c:\windows\Updates.exe 

MegaSecurity