Knightseven 1.0
(Backdoor.Win32.Knightseven.10)

by ?

Released in January 2001


Server:
dropped files:
c:\WINDOWS\sndctl32.exe   Size: 16.899 bytes
c:\WINDOWS\sndctl32.cfg 

port: 3627 TCP
     
startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "SndCtrl" 
c:\windows\system.ini, [boot] "shell" 


MegaSecurity