Retrieve 1.1
(Backdoor.Win32.MServ.b for logger.exe)
(Trojan-PSW.Retrieve.11)

by SpanxMFCS

Based on Girlfriend source

Compressed with ASPack

Released in July 1999


Retrive.exe:
added to registr:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Microsoft Access"
data: \Access.exe 



Server:
dropped file:
C:\WINDOWS\Access.exe 

size: 132.096 bytes 

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Microsoft Access" 

MegaSecurity