Silent Keylogger FTP
(Constructor.Win32.Banker.a)
(Trojan-Spy.Win32.Banker.gwy for Server)

by ?

Released in January 2008

Made in Poland

more versions





Server:
Dropped files:
c:\WINDOWS\system32\Session\svchost.exe
Size: 659,998 bytes 

Added to Registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr"
Data: 1 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Session"
Data: C:\WINDOWS\System32\Session\svchost.exe  




Tested on Windows XP
January 19, 2008

MegaSecurity