AHS 1.14
(Trojan-Spy.Win32.KeyLogger.ap)

by Czajnick

Written in Assembly, source included

Released in February 2003

Made in Poland


HTTP Server


Server:
dropped file:
c:\WINDOWS\SYSTEM\winhttp.exe 

size: 16.688 bytes 

port: 34280 TCP


startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Windows HTTP SubSystem" 

added:
c:\WINDOWS\SYSTEM\httpget.sys 
c:\WINDOWS\SYSTEM\httpkhk.dll 
c:\WINDOWS\SYSTEM\httpklg.sys 

MegaSecurity