Recently I have found an app called NTAdminRights.exe in the root of my C: Drive on one of my IIS servers in my DMZ. I am running on the assumption that this prog got there via and IIS exploit (that is the only world accessible service on this box, and of course, the root of C: is world writeable), and that whoever put this porg there did not get a foothold on the box itself since whoever he or she was, they left the damn thing there in plain sight. I could, however, be very wrong about all of this.
Whatever the case me be, I decomplied the program to produce the code below. Being a lowly sysadmin and not a programmer, I have no way of telling what the code does or tries to exploit. Can anyone help me out to this extent? Some of the comments in this code were most likely created by the decompiler.
Any help would make you god-like in my eyes.
