RysioLogger 3.1
(Backdoor.Win32.Reload.ak)

by rysio93

Written in Delphi

Released in February 2008

Made in Poland

more versions





Server
Dropped File:
c:\WINDOWS\g-g.exe
Size: 743,977 bytes 

Added to Registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr"
Data: 1 

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "AntyVirus"
Data: C:\Windows\g-g.exe 

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "gadu-gadu"
Data: %tmp%\g.g.exe 


Tested on Windows XP
February 05, 2008

MegaSecurity