Undetected


Name: Undetected
Aliases: Backdoor.TDS.Muerte, Backdoor.TDS.4F, 4Fuk, Trojan.Win32.TrojanRunner.Levil, TDS, Backdoor.TDS.SE, Un-Detected, U4, Muerter, X-Mas,
Ports: 777 (port can be changed)
Files: Undetected1.1.zip - 390,607 bytes Undetected2.2.zip - 415,753 bytes Undetected2.3a.zip - 41,243 bytes Undetected2.3SE.zip - 290,125 bytes Undetected3.0b.zip - 228,617 bytes Undetected3.1.zip - 289,212 bytes Undetected3.2.zip - 293,662 bytes Undetected3.3.zip - 489,813 bytes Undetected3.31.zip - 25,797 bytes Undetected3.32.zip - 24,801 bytes Undetected_xmas.zip - 395,890 bytes Udt31p.zip - 288,847 bytes Udt31s.zip - 18,687 bytes Udt33.zip - Uservof.zip - Udcompres.zip - Udinfo.zip - Udirchole.zip - Server.exe - 17,920 bytes Editserver.exe - 158,208 bytes Undetected1.1.exe - Userv331.exe - 22,122 bytes Userv332.exe - 21,098 bytes Umuerte.exe - 188,416 bytes Udt3b.exe - 192,152 bytes Udt31.exe - 208,896 bytes Udt33.exe - 292,352 bytes Udt4fuk.exe - 211,968 bytes Udtse.exe - 237,056 bytes Regcheck.exe - 19,968 bytes Cap.dll - 10,752 bytes Capture.dll - 89,600 bytes Fun.dll - 6,656 bytes Fun.dll - 12,288 bytes Fun.dll - 13,312 bytes Fun.dll - 20,480 bytes General.dll - 11,264 bytes Irchole.dll - 11,766 bytes Ucompress.dll - 15,360 bytes Ebios.vxd - Winloader.exe - 20,480 bytes Winload32.exe - 21,097 bytes Rnaap.exe - 20,480 bytes Compressor.exe - 14,336 bytes Winrun.exe - Msrexe.exe - 27,754 bytes Binder.mdl - 12,800 bytes Install.mdl - 12,800 bytes Rar_sfx.mdl - 12,800 bytes Plugex.dpr - 470 bytes Plugex.dpr - 726 bytes Skin.ini - 553 bytes Commands.cfg - 302 bytes Commands.cfg - 334 bytes Commands.cfg - 1,383 bytes Commands.cfg - 1,412 bytes Commands.cfg - 1,492 bytes
Created: June 2000
Requires:
Actions: Remote Access / Keylogger / Steals passwords / EXE binder
Registers: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCALE_MACHINES\Software\Classes\exefile\shell\open\command\
Notes: Works on Windows 95, 98 and ME.
Country: written in Rumania
Program: Written in Delphi.

© Copyright von Braun Consultants. This information may include technical inaccuracies or typographical errors. If you have any questions or further information about the actual trojan above, please contact Joakim von Braun at <joakim.von.braun@risab.se>