Trojan for Pitbul 1.0
(Backdoor.GF.13x)

by ?

Written in Delphi

Released in April 1999

Made in Russia


Server:
dropped file:
C:\WINDOWS\SYSTEM\Rundll16.exe 

size: 537.600 bytes

port: 64000 TCP

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices 
Old data: Rundll32.exe powrprof.dll,LoadCurrentPwrScheme 
New data: Rundll16.exe powrprof.dll,LoadCurrentPwrScheme 

MegaSecurity