Password
(Not detected by KAV on February 09, 2008)

by ReSoil

Written in Delphi

Released in December 2000


Server:
Dropped file:
c:\WINDOWS\SYSTEM\Pwd.exe 

size: 206.848 bytes

port: 2040 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Profile Manager" 

MegaSecurity