Winker (o)
(Backdoor.Winker.o)

by ?

The name "winker" is derived from "WinKernal"

Written in Visual C++

Made in China

more versions


dropped file:
c:\WINDOWS\system32\winkernal.exe
size: 51.200 bytes

port: 1050 UDP
 
startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "systhread"
data: C:\WINDOWS\System32\winkernal.exe

tested on Windows XP  

MegaSecurity