Visitor 1.1 Dropper
(Not detected by KAV on May 23, 2007)

by Error & Chochlik

Written in Delphi

Released in April 2004

Made in Poland

more versions


Client does drop:
c:\WINDOWS\SYSTEM\services.exe

size: 382.976 bytes

port: 1 TCP

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Zasobnik systemowy"





Server:
c:\WINDOWS\SYSTEM\services.exe 

size: 384.000 bytes

port: 1 TCP

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Zasobnik systemowy"

Does change the start page for explorer.

MegaSecurity