Remote Explorer 2000
(Backdoor.Win32.RE2K)

by Black Flash


Server:
dropped file:
C:\WINDOWS\SYSTEM\WIN128.EXE 

size: 21 KB

port: 1026, 2000 TCP
      1026, 2000 UDP
	  
startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run 

MegaSecurity