PwdSender 1.0
(Constructor.Win32.PwdSender.10)
(Trojan-Spy.Win32.Small.cm)

by T.C.

Released in April 2006


Server:
dropped files:
c:\WINDOWS\system32\REGSRV.exe     Size: 10,410 bytes 
c:\WINDOWS\system32\TCProto.dll    Size: 6,144 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "svchost"
data: C:\WINDOWS\System32\REGSRV.exe 




tested on Windows XP
May 09, 2006 

MegaSecurity