Main Menu
Home
Bookmark
Contact Us



 
Backdoor.TheThin Viruses Information

Name: Backdoor.TheThin
Category: Viruses
Description: Details
Backdoor.TheThing

This text was written by Peter Szor, Data Fellows Ltd
This backdoor copies itself with the EXPIORE.EXE name to the Windows directory and with the name of RUNDLI.EXE to the Windowssystem directory. It then modifies the SYSTEM.INI "shell" section to execute the program each time when Windows starts up, or the registry run field.
When executed, it tries to connect to wnp.icq.com with a user id of 111138. This id is owned by a hacker now calling himself "Of Hacker Anarchy Warrior". TheThing sends a message to him, and in this way, the hacker can see that the program is used on the actual machine. Then the local program starts to listen, therefore, the hacker can start to communicate and get information from that particular machine.
To remove it, someone has to delete this file and the RUNDLI.EXE from the system directory and fix the SYSTEM.INI shell section to remove the executed EXPIORE.EXE from there/or from the RUN field of the registry.



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Samp
Macro.Word.HaH
Skater.66
F1.33
Killer.96
I-Worm.NetSky.
Macro.Word.Boo
Midnight.235
Exploit.HTML.ObjDat
Macro.Word.Tele-Se


 


© 2006-2008 spyware32.com - Privacy Policy