WM Remote KeyLogger
(TrojanDropper.Win32.RSP.a)
(Backdoor.WMRemote)

by WishMaster

Made in Brazil


Server:
C:\WINDOWS\SYSTEM\IMAGEM.EXE 

size: 93 KB

port: 5025 TCP

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run 

Added:
c:\keylog.txt 

MegaSecurity