Winker (i)
(Backdoor.Win32.Winker.i)

by ?

The given name "winker" is derived from "WinKernal"

Written in Visual C++

Made in China

more versions


dropped files:

added to registry:
HKEY_LOCAL_MACHINE\SOFTWARE\WinKernal

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "systhread"
data: C:\WINDOWS\System32\winkernal.exe 



tested on Windows XP
May 05, 2005

MegaSecurity