Tyran 0.5a
(Backdoor.Win32.Agent.hqu)

by Kat

Written in MASM, Source included

Released in June 2003

Made in Poland


dropped file:
c:\WINDOWS\SYSTEM\sndrv.exe

size: 19.456 bytes 

port: 1986 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "sndrv"
data: C:\WINDOWS\SYSTEM\sndrv.exe 

MegaSecurity