Rorex (b)
(Backdoor.Win32.Rorex.b)

by ?

Written in Visual C++

more versions


screenshot of c:\photo.jpg


Backdoor.Win32.Rorex.b (1):
dropped files:
c:\WINDOWS\msacfg.exe    Size: 18,944 bytes
c:\WINDOWS\mslog.dat

startup:
c:\windows\system.ini, [boot] "shell" 





Backdoor.Win32.Rorex.b (2):
dropped files:
c:\WINDOWS\msacfg.exe         Size: 53,248 bytes
c:\photo.jpg 
c:\WINDOWS\padnote.exe 
c:\WINDOWS\wmouse.exe 
c:\WINDOWS\SYSTEM\padnote.dll 
c:\WINDOWS\mslog.dat 
C:\autoexec.bat: "C:\WINDOWS\wmouse.exe" 


startup:
c:\windows\system.ini, [boot] "shell" 

MegaSecurity