|
Tro.Backdoor.Remadmin.j Backdoor Information
| Name: |
Tro.Backdoor.Remadmin.j |
| Category: |
Backdoor |
| Advice: |
Remove |
| Risk: |
Severe Risk
Severe threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction and exploits are in the wild. There exists a high possibility of potential system damage or security flaw. Attacker has complete control over your computer or install new software on your machine. |
| Description:
|
Tro.Backdoor.Remadmin.j is a program used by attackers to take control of the infected machine.
Tro.Backdoor.Remadmin.j opens a backdoor on
port 4899 to allow attackers to perform various malicious activities. Tro.Backdoor.Remadmin.j also modifies the Windows hosts file to block access to security software websites/updates.
|
| Signatures:
|
process: svchost.exe: MD5 Hash: ac650a8e913d2f03f56...
process: service.exe: MD5 Hash: 0b71dba8fbbfb503fa7...
process: chkdskw.exe: MD5 Hash: 101b4c31697f6e832d7...
process: mstcpmon.exe: MD5 Hash: 681235038e1dcd1ca1a...
process: 101.exe: MD5 Hash: 0B61E3301672CCA05D2.. |
| Type: |
Backdoor - A Remote Administration Tool (RAT) is a Trojan type of software that when run, provides an attacker with the capability of remotely controlling a user's computer (victim) over the Internet. The attacker usually has full access to functions on the victim's computer. The victim's computer usually listens on the Internet for the attacker's commands. |
Top Backdoor Visited Pages:
Unicorn - 179 visits
SkatanBot - Alias: Backdoor.VB.kl - 93 visits
Backdoor:Win32/Lamebot.A - 84 visits
Delf.gb - Alias: RVP - 64 visits
BackDoor.Galapop.A - Alias: Trojan.Abwiz.D (Symantec), Galapoper (Mcafee) - 62 visits
Trojan.Backdoor.Darkmoon - Alias: Backdoor:Win32/Darkmoon.AZ - 58 visits
Trojan.Fakespy.A - Alias: Trojan.Zlob.B - 54 visits
Trojan.Backdoor.Codbot.O - Alias: W32/Codbot-O, Backdoor.Win32.Codbot.ah - 53 visits
RBot.sysdat - Alias: Backdoor:Win32/Rbot!E89C - 53 visits
Backdoor.Perl.AEI.16 - 52 visits
Random Backdoor Pages:
SdBot.msnmsg - Alias: Backdoor:Win32/Sdbot
RBot.p2pnetworking - Alias: Backdoor:Win32/Rbot
NetBull.11
Unicorn
ASP.Ace.f
TBT Nightmare - Alias: Backdoor.VB.jl
Trojan.Backdoor.AVUpdateScheduler - Alias: Trojan.Backdoor.Heplane, Anti-Virus Update Scheduler V1.39.12R, TrojanProxy:Win32/Ranky.DP
IRC Spybot - Alias: Backdoor.SpyBot.gen
Lixy - Alias: HTMLEdit
Bear and Tiger
|