Shell (c)
(Backdoor.Win32.Sheldor.c)

by ?

Written in Borland C++, compressed with ASPack




dropped file:
c:\WINDOWS\system32\shellexpi.exe
size: 311.296 bytes

added to registry:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Explorer"

tested on Windows XP

MegaSecurity