Antylamus 0.2
(Backdoor.Win32.Delf.jb)

by Slawek

Written in Delphi

Released in November 2003

Made in Poland





Server:
dropped filr:
c:\WINDOWS\SYSTEM\WinTask.exe 

size: 550.912 bytes 

port: 1900  TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Microsoft dllLoader" 

added:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableRegistryTools" 

MegaSecurity