Orig
(Backdoor.Win32.Orig)

by ?


Server:
dropped file:
C:\WINDOWS\UNISTB16.EXE

size: 56 KB

startup:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run 
HKCU\Software\Mirabilis\ICQ\Agent\Apps
HKLM\Software\Microsoft\Windows\CurrentVersion\Run 
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices 

MegaSecurity