Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 4th, 2003, 04:24 PM
FanJ
 
Posts: n/a
Default Troj/Tunnel-A ; Aliases: Backdoor.Checkesp

http://www.sophos.com/virusinfo/anal...ojtunnela.html

Description
Troj/Tunnel-A is a backdoor Trojan. When the Trojan is first executed a copy will be created in the system folder with the filename sys64.exe and the following registry entry will be created so that the Trojan is run when Windows starts up:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\tunelling = sys64.exe

Troj/Tunnel-A begins by connecting to a site run by the attacker to inform them that the computer has been compromised. The Trojan will then listen for commands from the attacker.

The Trojan also listens on port 80, the default HTTP port, and redirects network traffic on that port to the attacker.

  #2  
Old June 4th, 2003, 05:29 PM
Longthing Longthing is offline
Infrequent Poster
 
Join Date: Jul 2002
Posts: 40
Default Re:Troj/Tunnel-A ; Aliases: Backdoor.Checkesp

Got already a sample here.
  #3  
Old June 4th, 2003, 07:30 PM
FanJ
 
Posts: n/a
Default Re:Troj/Tunnel-A ; Aliases: Backdoor.Checkesp

Quote:
quoting: Longthing link=board=30;threadid=9910;start=0#msg64595 date=1054762160]
Got already a sample here.

Hi Jan,
I hope you could get rid of it !

Cheers, Jan.
  #4  
Old June 5th, 2003, 12:51 AM
Longthing Longthing is offline
Infrequent Poster
 
Join Date: Jul 2002
Posts: 40
Default Re:Troj/Tunnel-A ; Aliases: Backdoor.Checkesp

No problem. Didn't execute it.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:38 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums