Remote Keylogger
(Trojan.Win32.Genome.bjgh)
(Trojan.Win32.Genome.uxd)

by noface

Written in Visual Basic

Released in December 2006

more versions




Server:
dropped file:
c:\WINDOWS\security\logs\config.exe
size: 45,056 bytes 

port: 1840 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "config"
data: c:\WINDOWS\security\logs\config.exe 



Tested on Windows XP
January 18, 2007

MegaSecurity