Pitfall 1.0
(Trojan-Dropper.Win32.EliteWrap.103)

by IntrudeR

Released in February 2000

Made in Brazil

more versions




Pitfall.exe size: 167.406 bytes
dropped files:
c:\WINDOWS\Ms.Win32.exe                   size: 83.968 bytes  (infected: Win95.CIH, disinfected: not detected)
c:\WINDOWS\TEMP\eW_22B6.TMP\win32log.exe  size: 75.681 bytes  (TrojanDropper.Win32.EliteWrap.103)
c:\WINDOWS\TEMP\eW_22B6.TMP\win32pit.exe  size: 83.968 bytes  (Not detected)
c:\WINDOWS\TEMP\eW_22C0.TMP\keylog.exe    size: 9.355 bytes   (Not detected)
c:\WINDOWS\TEMP\eW_22C0.TMP\qpro200.dll   size: 58.544 bytes 

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Win32Load"
data: C:\WINDOWS\Ms.Win32.exe
 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices "Win32Load"
data: C:\WINDOWS\Ms.Win32.exe 
	
port: 1991 TCP

tested on Windows 98
November 08, 2004

MegaSecurity