SoniTroyen
(Backdoor.Win32.Sonitro)

by ?

Written in Delphi

Made in France


Server:
dropped file:
c:\progra~1\Info.exe 

size: 552.960 bytes

port: 5555 TCP

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "SysInfo" 

MegaSecurity