Winker (b)
(Backdoor.Win32.Winker.b)

by ?

The name "winker" is derived from "WinKernal"

Internal Name: AntiSars

Written in Visual C++

Made in China

more versions


Server:
size: 45.056 bytes

registry added:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "systhread" 
data: C:\WINNT\System32\winkernal.exe 

HKEY_LOCAL_MACHINE\SOFTWARE\WinKernal 

Tested on win2000

MegaSecurity