by ?
Written in Delphi, compressed with UPX
dropped file: c:\WINNT\SHEXT.EXE size: 421.888 bytes startup: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "shellext.exe" data: shext.exe does (try to) connect to an address in Russia on port 21 tested on win2000MegaSecurity