Email Password Sender


Name: Email Password Sender
Aliases: EPS, EPS II,
Ports: 25 (port can not be changed)
Files: Eps.zip - 89,595 bytes Eps1.09.zip - 115,627 bytes Eps1.51.zip - 267,277 bytes Eps151.zip - 268,508 bytes Eps161.zip - 82,317 bytes Eps1.61.zip - 89,689 bytes Eps166.zip - 65,001 bytes Config.exe - 9,216 bytes Config.exe - 12,288 bytes Config.exe - 23,985 bytes Config.exe - 26,112 bytes Config.exe - 40,448 bytes Config.exe - 47,66 bytes Eps.exe - 31,774 bytes Eps.exe - 32,256 bytes Eps.exe - 47,140 bytes Eps.exe - 49,408 bytes Eps.exe - 49,664 bytes Eps.exe - 52,492 bytes Eps.exe - 72,964 bytes Eps16.exe - [15,7 kb]Eps161.exe - 16,084 bytes Filed.exe - 26,624 bytes Filed.exe - 57,344 bytes Winstat.exe - Priocol.exe.exe - Priocol.dll - Pricoll.dll - 77,652 bytes Pricol.exe - Bintouue.exe - 41,472 bytes Cryptuue.exe - 41,984 bytes Decryptuue.exe - 43,008 bytes Uuetobin.exe - 42,496 bytes - 13,528 bytes
Created:
Requires:
Actions: Steals passwords / ICQ trojan
Registers: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Mirabilis\ICQ\Agent\Apps\Run\
HKEY_CURRENT_USER\Software\Mirabilis\ICQ\Owners\
Notes: Works on Windows 95, 98 and NT. NT compatibility added in v 1.63. From v 1.62 the trojan is called EPS II.
Country: written in Russia
Program: Written in Visual C++.

© Copyright von Braun Consultants. This information may include technical inaccuracies or typographical errors. If you have any questions or further information about the actual trojan above, please contact Joakim von Braun at <joakim.von.braun@risab.se>