mE$$iAh 1.0 v1
(Backdoor.Win32.Messah.10 for Client)
(Backdoor.Win32.Delf.ap for Server)

by -=|R|S|C|=-

Written in Delphi, compressed with ASPack, source included

Released in February 2002

Made in Hungary

more versions


Server:
dropped file:
c:\WINDOWS\SYSTEM\winapi.exe 
 
size: 197.159 bytes 

port: 4567 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices "JYService" 

file added:
c:\WINDOWS\SYSTEM\wina386.dll 

registry added:
HKEY_LOCAL_MACHINE\Software\Spy 

MegaSecurity