|
| Name: | Backage |
| Aliases: | BackDoor-HC, |
| Ports: | 334, 411, 5333 |
| Files: | Backage.3.zip - 140,409 bytes Backage3.0.zip - 140,778 bytes Backage3.0.1.zip - 156,192 bytes Backage3.1.zip - 188,374 bytes Backage3.1.1.zip - 221,862 bytes Backageserver3.1a.zip - 35,368 bytes Backage3.2seb.zip - 120,198 bytes Backage 3.2 se.exe - 933,888 bytes Backageclient.exe - 315,904 bytes Backageclient.exe - 339,456 bytes Backageclient.exe - 630,784 bytes Backageserver.exe - 98,816 bytes Backageserver.exe - 114,688 bytes Backageserver.exe - 118,784 bytes Backageserver.exe - 120,320 bytes Backageserver2.exe - 118,784 bytes Server.exe - Desintall.exe - 37,888 bytes Desintall.exe - 65,536 bytes Winstop32.exe - Mskernel16.exe - Edit server.exe - 69,632 bytes Backage32se.bagage - 812 bytes Backage3.ini - 879 bytes Skin.ini - 632 bytes Makeskinz.exe - 217,088 bytes |
| Created: | July 2000 |
| Requires: | N/A |
| Actions: | Remote Access |
| | Alters Win.ini and System.ini. A servereditor makes it possible for an intruder to change the port used and the UIN to notify upon a new succesful installation. |
| Versions: | 3.0, 3.0.1, 3.1, 3.1.1, 3.1.2, 3.2 SE beta, |
| Registers: | HCU\Software\Microsoft\Windows\CurrentVersion\Run\ HKEY_LOCAL_M ACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\ HCU\Soft ware\Microsoft\Windows\CurrentVersion\RunOnce\ HU\.Default\Software\Micr osoft\Windows\CurrentVersion\Run\ HU\.Default\Software\Microsoft\Windows \CurrentVersion\RunOnce\ HLM\Software\Microsoft\Windows\CurrentVe rsion\RunService\ HU\.Default\Software\Win\Run\ |
| Notes: | Works on Windows 95, 98 and ME. |
| Country: | written in France |
| Program: | Written in Visual Basic 5 and 6. |
Using the Process Monitor from AATools, you will see whether any foreign
programs are running on your computer. If you find some unwanted program, you
can terminate it by clicking the 'Terminate Process' button on the Toolbar.
Using the AATools Network Monitor, you can see what ports are in use on
your local PC for connection with remote systems (LAN/Internet). On Windows
NT/2000/XP the Network Monitor will display you the services that are active on
the ports, and map the ports to their respective applications. If you register
port probes directed against ports that are normally not used, it is possible
that someone is trying to connect to a Trojan inside your network. Using the
Registry Cleaner (Startup section) from AATools, you will see
the list of programs that are registered under Run, RunOnce, RunOnceEx and
RunService registry keys. So you can find out what programs are started behind
your back. You should check these programs to see they are legitimate ones but
not Trojans programs.
0-C | D-H | I-N
| O-S | T-Z
If you have any questions or information about ports used by Trojans not
listed above, please contact us. |