Archive Helmet Icon Archive A Reconstructed © MegaSecurity Database

Win-Spy 9.0 build 175

Released 18 years, 8 months ago. August 2007

Copyright © MegaSecurity

By BC Computing


Informations
Author BC Computing
Family Win-Spy
Category Remote Access
Version Win-Spy 9.0 build 175
Released Date Aug 2007, 18 years, 8 months ago.
Language Visual Basic
Additional Information
Remote Install File:
dropped files:
c:\WINDOWS\msmsgrs.exe                   Size: 94,208 bytes 
c:\WINDOWS\msn64.exe                     Size: 106,496 bytes 
c:\WINDOWS\outlookrem.exe                Size: 57,344 bytes 
c:\WINDOWS\proxy32.exe                   Size: 344,064 bytes 
c:\WINDOWS\rsmpls.exe                    Size: 61,440 bytes 
c:\WINDOWS\ruto32.exe                    Size: 40,960 bytes 
c:\WINDOWS\winup32.exe                   Size: 69,632 bytes 
c:\WINDOWS\vzones\services.exe           Size: 122,880 bytes 
c:\WINDOWS\vzones\smss.exe               Size: 176,128 bytes 
c:\WINDOWS\system32\CSpool\rsver.dll     Size: 92,160 bytes 
c:\WINDOWS\system32\CSpool\setup1.exe    Size: 131,072 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "ccAppRemXP"
data: C:\WINDOWS\msn64.exe 


tested on Windows XP
September 05, 2007

This archive is an almost-complete reconstruction of the legendary Mega Security (also known as Kobayashi), a premier 90s-era "Trojan Database" where malware authors once showcased their work. After a decade offline, the site was brought back in August 2024 by its original creator, MasterRat, who authorized the Malware Gallery to host this modernized, searchable version of the collection. While the original site remains available for those seeking a nostalgic, old-school experience, we are proud to continue its legacy here. Full credit and thanks go to MasterRat and the retired Mega Security staff for their years of dedicated work in cataloging these historical samples.