by MEHRDAD
Released in September 2004
Server: dropped files: c:\WINNT\tcpctrl.exe size: 944 bytes c:\WINNT\msagent\update.exe size: 33.503 bytes c:\WINNT\system32\Decoder.dll size: 6.144 bytes startup: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows "load" data: C:\WINNT\tcpctrl.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell" data: explorer.exe C:\WINNT\msagent\update.exe tested on Win2000MegaSecurity