|
|||||||||||
|
Possible new backdoor: mspx-smss.exe ?
From: Sven Pechler <helpdesk(at)tm.tue.nl>
Date: Fri Feb 21 2003 - 06:57:16 EST ('binary' encoding is not supported, stored as-is) Hello,
Last week we have detected a possibly new backdoor trojan on a Windows
2000 computer.
The developer of the software made a great deal of effort to make it hidden. The process is not visible in the Windows Task Manager. The directories containing the files are not visible to the local administrator. Parts of the 'services' registry keys are made hidden and no TCP 'listening'-ports can be seen using the 'netstat' command. I collected the following files:
In C:\WINNT\SYSTEM32:
Contents of C:\WINNT\SYSTEM32\MUI\DISPSPEC\MSPXCOMMON\COM1\MSPX directory: 19-02-2003 14:55 The directory above is NOT VISIBLE on 'infected' computers. But due to a programming flaw an empty directory C:\DEV is always created, because somewhere in the program the output is incorrectly redirected to /dev/null. Is this really an unknown backdoor? No anti virus software seem to detect is, nor programs like MooSoft's 'The Cleaner'. -Sven
Do you know the base address of the Global Offset Table (GOT) on a Solaris 8
box?
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:58 EDT |
||||||||||
|
|||||||||||