lsd 2.0
(Trojan-Downloader.Win32.Apher.gen)

by hybrid

Released in October 2006


Title: lsd
Version: 2.0
Build Date: 25,October,2006

** Stubs are detected by heuristics so don't be bitching k?, i may add 
   some sort of encryption to a later release, XOR or something.

** I realise that the path option is flawed as you may specify a drive
   that doesn't exist, but if im not mistaken you can use for example:
   "/" and it will download to the drive which is currently
   in use.

Features:

> Two differant stubs, a regular non-fwb and a fwb+ with melt
> Super small size for both stubs but the fwb+ stub is bigger, Obviously
> Option to pack with FSG
> Uses drocon's rt32 injection library

Specification:

> 40 bytes reserved for URL and 30 for Path
> Stub Sizes:
	
  Regular stub Unpacked is exactly 1kb (1024 bytes) without settings
  Regular stub Packed is 789 bytes without settings

  Fwb stub Unpacked is exactly 2kb (2048 bytes) without settings
  Fwb stub Packed is 1.07kb (1097 bytes) without settings



tested on Windows XP
November 24, 2006

MegaSecurity