Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 12-10-2003, 07:09
thinkping
 
Posts: n/a
Question New bad BAckdoor-Proggi?

This seems to be a very bad backdoorprogramm, kills antivirus and firewall, made it unable to execute any exefiles and shells exept command.com under NT, stays aktive after new Windows2k installation? I was surprised...after the third windowsinstall it was clean

maybe someone knows it an has more infos
Attached Files
File Type: zip backdoors_winx32sys.zip (721.3 KB, 24 views)
Reply With Quote
  #2  
Old 12-10-2003, 15:33
TQN TQN is offline
VIP
 
Join Date: Apr 2003
Location: Vietnam
Posts: 343
Rept. Given: 142
Rept. Rcvd 20 Times in 12 Posts
Thanks Given: 169
Thanks Rcvd at 130 Times in 43 Posts
TQN Reputation: 20
Hi thinkping !
You don't need to reinstall Windows. You need follow below steps to repair your Windows:
- Use TaskManager to kill winx32sys.exe
- Delete two file winx32sys.exe and win386sys.exe in WinNT\system32 directory
- Delete two key of winx32sys.exe in registry: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and RunServices
- Delete key of winx32sys.exe in win.ini:
[windows]
Run=c:\winnt\system32\winx32sys.exe
- Delete key of winx32sys.exe in system.ini:
[boot]
Shell=Explorer.exe c:\winnt\system32\winx32sys.exe
- Repair the key of exefile in registry:
HKLM\SOFTWARE\Classes\exefile\shell\open\command:
c:\winnt\system32\win386sys.exe PASS "%1" %*
to "%1" %*
I used filemon and regmon of SysInternal to find the action of this backdoor program. It was written in Delphi.
Good luck to you.
TQN
Reply With Quote
  #3  
Old 12-11-2003, 02:34
thinkping
 
Posts: n/a
-

ok, thanks that helps.

but taskmanager couldn't killthe application, i use far (wxw.rarlab.com), a nortoncommanderclone for NT.

many thanx
Reply With Quote
  #4  
Old 12-16-2003, 04:08
c4p0ne's Avatar
c4p0ne c4p0ne is offline
Friend
 
Join Date: Jul 2002
Location: n/a
Posts: 83
Rept. Given: 1
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 2
Thanks Rcvd at 0 Times in 0 Posts
c4p0ne Reputation: 1
Red face erm..

This is by no means "new". It is an Optix Pro server by evileyesoftware.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 06:13.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )