Poison Ivy 2.1.2
(Backdoor.Win32.PoisonIvy.d)
(Trojan.Win32.Small.js)

by shapeless

Written in Delphi

Released in November 2006

more versions

 


GENERAL FEATURE LIST
firewall bypassing, reverse connection, ARC4 encrypted communications, transparent compression of transfers and
communications, full-featured file, registry, services and process manager, relay server, view installed applications (some
support remote silent uninstallation), key logger, socks4/5 server, traffic sniffer, remote screen capture and web cam
viewing, password manager (IE cached passwords, MSN passwords, Firefox cached passwords, wireless zero configuration
passwords, LM/NTLM hashes), runs on restricted accounts.



Server:
size: 7,680 bytes

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{255959D1-EAA2-3478-0804-030805050803} "StubPath"
data: C:\WINDOWS\System32\svchost.exe


tested on Windows XP
November 14, 2006

MegaSecurity