Lohocla
(Backdoor.Win32.Lohocla)

by ?

Written in Borland C++, compressed with FSG

Made in France





dropped file:
c:\WINDOWS\system32\E05F30E0.exe
size: 213,728 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "E05F30E0"
data: C:\WINDOWS\System32\E05F30E0.exe 

attempts to connect to an IRC server



tested on Windows XP
May 07, 2005

MegaSecurity