arplhmd spy
(Trojan-Spy.Win32.Bancos.iq)

by arplhmd

Written in Visual Basic

Released in July 2004

Made in Brazil

more by arplhmd




hmdspy.exe:
size: 348.672 bytes

port: 1068, 1069 TCP

added to registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "hmdspy"

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_FASTFAT\0000\Control "ActiveService"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FASTFAT\0000\Control "ActiveService" 

MegaSecurity