Isen (a)
(Backdoor.Win32.Isen.a)

by ?

Written in , compressed with UPX


Isen on Windows 98




Windows 98:
dropped file:
c:\WINDOWS\SYSTEM\msnetrpc.exe
size: 17.408 bytes 



Windows XP:
added to registry (visible changes):
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MSNETRPC
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msnetrpc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\C
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSNETRPC
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msnetrpc

Backdoor.Isen.Rootkit is a backdoor Trojan horse that hides processes and files. 
In addition, the Trojan also provides remote access to a compromised system. 
Symantec



tested on Windows XP & Windows 98
April 28, 2005

MegaSecurity