Alcarys.G


Name: Alcarys.G
Aliases: W32.Alcarys.G@mm, W97M.Alcarys.G@mm, Neysid, W32.Neysid@mm,
Ports:
Files: File*.*.exe - (* = 7 respectivly 8 random numbers)Disney.scr - 19,456 bytes Movie.exe - 19,456 bytes Screenxx.scr - 19,456 bytes File1980.com - 19,456 bytes Alco.com - 19,456 bytes Hacktool.co_ - 19,456 bytes Porno.scr - 19,456 bytes Windows.exe - 19,456 bytes Windows.scr - 19,456 bytes Winstart.com - 19,456 bytes Msmsgs.exe - 19,456 bytes Rundll64.exe - 19,456 bytes Reg.exe - 19,456 bytes Beatles white album full compressed.exe - 19,456 bytes Dungeons and dragons 2002.exe - 19,456 bytes Gameboy Emulator.exe - 19,456 bytes Gran Turismo Hacks.exe - 19,456 bytes Looneytunes.scr Marvel Superheroes.exe Mirc Hack.exe Ms Office Xp Password Unlocker.exe Password_Qwwodkd1192pw.exe Visual Interpretation.scr The Osbournes.scrVisual Basic .Net Tutor.exe Xbox Emulator compressed.exe Benjaminwormremover.exe Blade 2 Full Download.exe Jenna Jameson 2002.scr Classified.exe Eminem Show Full Album Fetcher.exe F*Ck Of The Year 2001.scr Kelly Osbourne Close Up.scr New Gorillaz Single_exe Version_.exe Palm Os Software Upgrade.exe Robot Wars - Pc Version.exe Shrek Full Downloader -Hehehe-.exe Spiderman_Never_Been_Seen_Footage_Download.exe Star Wars Ii - Full Downloader.exe Tekken 5 Beta Downloader.exe Win.exe - 19,456 bytes Clickme.exe - 19,456 bytes Watchme.exe - 19,456 bytes Blank.html. 321 bytes Doc.wps - 1,950 bytes Nor.wps - 839 bytes Porno.doc - 49,152 bytes Newdocument.doc - 49,152 bytes .Normal.dot - ??? bytes Xls.wps - 1,829 bytes Xxxmovie.xls - 47,616 bytes V.reg - 428 bytes V.vbs - 114 bytes Pornview.exe - 19,456 bytes Viewer.dll - 19,456 bytes Start.bat - 146 bytes Readme.txt - 43 bytes
Created:
Requires:
Actions: Virus / Worm / Mail trojan / IRC trojan / Kazaa trojan
Registers: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\
HKEY_CURRENT_USER\Software\Kazaa\LocalContent
HKEY_CLASSES_ROOT\JSFile\Shell\Open\Command
HKEY_CLASSES_ROOT\JSFile\Shell\Open2\Command
HKEY_CLASSES_ROOT\mp3file\shell\open\command
HKEY_CLASSES_ROOT\mp3file\shell\play\command
HKEY_CLASSES_ROOT\txtfile\shell\open\command
HKEY_CLASSES_ROOT\VBSFile\Shell\Open\Command
HKEY_CLASSES_ROOT\VBSFile\Shell\Open2\Command
Notes: Works on Windows 98, ME, NT, 2000 and XP, together with MS Outlook, mIRC and Kazaa P2P networks.
Country:
Program: Written in Visual Basic.

© Copyright von Braun Consultants. This information may include technical inaccuracies or typographical errors. If you have any questions or further information about the actual trojan above, please contact Joakim von Braun at <joakim.von.braun@risab.se>