Red ZONE 6.5 (a)
(Trojan-PSW.Win32.RedZone.65.a for Server)
(Trojan-PSW.Win32.RedZone.55 for configurator)

by Teshke

Written in Delphi, compressed with UPX

Released in August 2003

Made in Russia

more versions




Server:
dropped file:
c:\WINDOWS\6.EXE 

size: 69.683 bytes

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "service.exe" 

registry added:
HKEY_CURRENT_USER\Software\Mirabilis\ICQ\NewOwners 
HKEY_CURRENT_USER\Software\RZ6 
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Network\LanMan 

MegaSecurity