Remote Revise 1.7 beta
(Backdoor.Win32.Revise.17)

by W@SyL

Written in Delphi, Client is compressed with UPX

Released on May 2003

Made in Poland

more versions


Server:
dropped file:
c:\WINDOWS\SYSTEM\SYSTRAY32C.EXE 

size: 565.248 bytes 

port: 4545 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices "SysTray32" 

MegaSecurity