Opwin Trojan 1.1
(Backdoor.Win32.Opwin.11)

by Mister Mog

Released in June 2000

Made in France


Server:
dropped files:
c:\WINDOWS\Progr.exe      size: 258.560 bytes 
c:\WINDOWS\scanregw..exe  size: 258.560 bytes 

port: 10000, 10005 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "ScanRegistry-"
data: C:\WINDOWS\SCANREGW..EXE 

c:\windows\system.ini, [boot] "shell"
c:\windows\win.ini, [windows] "load" 

registry key added:
HKEY_CLASSES_ROOT\Essai\shell\open\command "Opw"

MegaSecurity