Archive Helmet Icon Archive A Reconstructed © MegaSecurity Database

Spy Agent 1.2

Released 18 years, 9 months ago. July 2007

Copyright © MegaSecurity

By AliCaNelKa


Spy Agent 1.2
Informations
From Turkey
Author AliCaNelKa
Family Spy Agent
Category Information Stealer
Version Spy Agent 1.2
Released Date Jul 2007, 18 years, 9 months ago.
Language Delphi
Additional Information
Server
Dropped Files:
c:\WINDOWS\Amcam13.ini     Size: 14 bytes 
c:\WINDOWS\ayar.ini        Size: 105 bytes 
c:\WINDOWS\openssl.cnf     Size: 9,374 bytes 
c:\WINDOWS\services.ini    Size: 99 bytes 
c:\WINDOWS\winlogon.exe    Size: 426,102 bytes 

Added to Registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "System"
Data: \windows\winlogon.exe 




Tested on Windows XP
September 25, 2007

Author Information / Description
Password Stealer for
  
    * MSN Messenger
    * Windows Messenger (In Windows XP)
    * Windows Live Messenger (In Windows XP And Vista)
    * Yahoo Messenger (Versions 5.x and 6.x)
    * Google Talk
    * ICQ Lite 4.x/5.x/2003
    * AOL Instant Messenger (only older versions, the password in newer versions of AIM cannot be recovered)
    * AOL Instant Messenger/Netscape 7
    * Trillian
    * Miranda
    * GAIM

This archive is an almost-complete reconstruction of the legendary Mega Security (also known as Kobayashi), a premier 90s-era "Trojan Database" where malware authors once showcased their work. After a decade offline, the site was brought back in August 2024 by its original creator, MasterRat, who authorized the Malware Gallery to host this modernized, searchable version of the collection. While the original site remains available for those seeking a nostalgic, old-school experience, we are proud to continue its legacy here. Full credit and thanks go to MasterRat and the retired Mega Security staff for their years of dedicated work in cataloging these historical samples.