Thing 1.6 (e) Server
(Backdoor.Win32.TheThing.16.e)

by Blade

Made in Romania

more versions


dropped file:
c:\WINDOWS\netlog32.exe
size: 8,192 bytes 

port: 6000 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Shell"
old data: Explorer.exe 
new data: explorer.exe netlog32.exe 

tested on Windows XP
November 11, 2005

MegaSecurity