Tibia Stealer 0.2
(Trojan-PSW.Win32.Tibia.an)

by Amper

Written in Delphi

Released in May 2007

Made in Poland


dropped file:
c:\WINDOWS\system\system.exe
size: 200,196 bytes 

added to registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "system"
data: c:\windows\system\system.exe 

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile "EnableFirewall"
data: 00, 00, 00, 00 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile "EnableFirewall"
data: 00, 00, 00, 00 




tested on Windows XP
May 14, 2007

MegaSecurity