by Alchemist
Written in Visual Basic
Released in September 2003
Server:
c:\WINDOWS\Csrss.exe
size: 76.085 bytes (compressed)
port: 5888 TCP
startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Runtime Process"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices "Runtime
HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6017B} "StubPath"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Runtime Process"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
c:\windows\system.ini, [boot] "shell"
c:\windows\win.ini, [windows] "load"
c:\windows\win.ini, [windows] "run"
registry added:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run "Runtime Process"
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\windows\Run "Runtime Process"
MegaSecurity