DLP
(Backdoor.Win32.Loselove)

by ?

Written in Delphi

Released in February 2002

Made in China


Client:
port: 8130, 8131, 8322, 8329, 9329 TCP


Server:
C:\WINDOWS\Syslog.exe 
C:\WINDOWS\system\Syslp.exe 

size: 457.216 bytes


port: 8110, 8111, 8301, 8302, 9301 TCP

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Syslog" 
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Systems" 
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Systray" 
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices "SysExplore" 
c:\windows\win.ini,  "run" 

MegaSecurity