Winker (j)
(Backdoor.Win32.Winker.j)

by ?

The given name "winker" is derived from "WinKernal"

Written in Visual C++

Made in China

more versions


dropped files:
c:\WINDOWS\system32\hello.exe     size: 35.840 bytes 
c:\WINDOWS\system32\iexplore.dll  size: 35.840 bytes

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "systhread"
data: C:\WINDOWS\System32\hello.exe 

tested on Windows XP 

MegaSecurity