WinKernal (a)
(Backdoor.Win32.Winker.a)

by ?

Internal Name: AntiSars

Written in Visual C++

Made in China

more versions


dropped files:
C:\WINDOWS\SYSTEM\hello.exe (win98)
C:\WINNT\System32\hello.exe (win2000)

size: 204.800 bytes

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "systhread" 

MegaSecurity