Description: 2003 remote control, the domestic users less aware of the services to generate client will copy itself to% SYSTEM% directory and renamed PROSIAK_TROJAN.EXE, the presence of memory. And delete the% SYSTEM% directory WINDLL32.EXE, VBRUN60. EXE, GDI32.EXE, MSJET32.EXE and RUNDLL32.EXE file
To Search:
- [csystem21] - File copy operations
- [jbcfile] - a copy of the document Liezi, they can r
- [dsf6.85source] - DynamicSkinForm Finial 6.85_ complete tr
- [4015216743] - delphi indy9.0.18 Package
- [c++] - DFA individual software when installing
- [my] - Online game Dungeons
- [muou] - As the Trojans have three service client
- [vvyang_AdpSpy] - AdpSpy NDIS 网卡 网络接口
File list (Check if you may need any files):
Client
......\english.lng
......\GAUGES.PAS
......\lang.pas
......\lang_eng.pas
......\main.dfm
......\main.pas
......\polish.lng
......\prosiak.ini
......\pro_cli.cfg
......\pro_cli.dof
......\pro_cli.dpr
......\pro_cli.res
......\scanner.pas
......\stale.pas
......\toolsy.pas
Editserver
..........\konfig.cfg
..........\konfig.dof
..........\konfig.dpr
..........\konfig.res
..........\main.dfm
..........\main.pas
SERVER07
........\figle.pas
........\GAUGES.PAS
........\httpd.pas
........\imager.dfm
........\imager.pas
........\KeySpy.d16
........\KeySpy.dcr
........\KeySpy.dcu
........\KeySpy.pas
........\KLayouts.inc
........\konfig.pas
........\main.dfm
........\main.pas
........\prosiak.dof
........\prosiak.dpr
........\prosiak.res
........\sharing.pas
........\shield.dfm
........\shield.pas
........\siec.pas
........\skrypt.pas
........\stale.pas
........\toolz.pas
........\windoz.pas