Alop
(Backdoor.Win32.Alop)

by @p0ll0

Internal Name: wmts

Compressed with ASPack




Server:
dropped file:
c:\WINDOWS\wmts.exe 

size: 60.416 bytes 

port: 1028 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "wmts" 

added:
HKEY_LOCAL_MACHINE\Software\Microsoft\DownloadManager 

MegaSecurity