ExpIorer
(Backdoor.Win32.Explore)

by ?

Compressed with PECompact





ExpIorer:
dropped file:
c:\WINNT\system32\expIorer.exe

size: 19.456 bytes
 
port: 113 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Configuration Loader"
data: expIorer.exe
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices "Configuration Loader"
data: expIorer.exe

tested on Win2000

MegaSecurity