HiddenSpy 1.0
(Trojan.Win32.Genome.adhc)
(Trojan.Win32.Swisyn.oy)

by r@nger


Released in November 2007

Made in Turkey

more versions


Server
Dropped Files:
c:\WINDOWS\system32\drivers\file.exe       Size: 16,384 bytes 
c:\WINDOWS\system32\drivers\svchost.EXE    Size: 373,267 bytes 
c:\WINDOWS\system32\drivers\userinf.exe    Size: 58,368 bytes 
c:\WINDOWS\system32\drivers\etc\hosts	

Added to Registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "svchost"
Data: C:\WINDOWS\system32\drivers\svchost.EXE 
	
	
	
Tested on Windows XP
December 26, 2007

MegaSecurity