by ?
Compressed with PECompact
Made in Korea (?)
dropped files: c:\Documents and Settings\%user%\Application Data\Microsoft\hkreqv2.dll size: 188.416 bytes c:\Documents and Settings\%user%\Application Data\Microsoft\thememan.exe size: 27.862 bytes added to registry: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "thememan" data: C:\Documents and Settings\%user%\Application Data\Microsoft\thememan.exe The backdoor is related to this site: www.utility-carfax.com tested on Windows XP December 21, 2004MegaSecurity