The RAT 2.0
(Trojan-Spy.Win32.TheRat.20)

by HandyCat

Written in Microsoft Visual C++

Released in January 2005

Made in Russia

more versions


dropped files:
c:\therat.log    Size: 0 bytes 
c:\WINDOWS\system32\32syslib.dll  size: 5,632 bytes 
c:\WINDOWS\system32\rat.dat       size: 17,408 bytes 
c:\WINDOWS\system32\socketme.exe  size: 17,408 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "socketme"
data: socketme.exe 



tested on Windows XP
January 23, 2005

MegaSecurity