Network Administration 1.6
(Backdoor.Win32.Antilam.20.q)

by toxed

Written in Delphi

Released in June 2003

Made in Russia


Server:
dropped file:
c:\WINNT\NAS.exe
size: 601 090 bytes 

port: 53559, 20226 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Network Administration"
data: C:\WINNT\NAS.exe 



tested on Windows 2000
January 31, 2005

MegaSecurity