Winker (e)
(Backdoor.Win32.Winker.e)

by ?

The given name "winker" is derived from "WinKernal"

Written in Visual C++, compressed with UPX

Made in China

more versions


startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "systhread"
data: C:\WINDOWS\System32\winkernal.exe 



MegaSecurity