Home
Articles
Spyware Research
Support
Scan Now
Purchase
F.A.Q.
Top 25 Spyware:
Glossary Latest Detections ![]() |
RAT/MassakerAlias: Backdoor.Massaker.11.c, Massaker
Description: This program was designed for illegal controlling of other people's computers. The hacker infects the victim's machine via the e-mail or File and Print Sharing with a "server" program. He can later access the infected machine via a "client". The functions of a RAT may vary, depending on the needs of the hacker. Some may just do nasty things, while the user is working. Other can steal vital information and delete files. Once inside the system, the virus opens a default TCP port 7119 and awaits commands from the intruder. Several versions (Massaker 1.1, Massaker 1.1b, Massaker 1.2, Massaker 1.2b) of this pest appeared in the internet from January 2002 to February 2004. The pest is written in Visual Basic and compressed with UPX. The author of this pest is a hacker called InFeCtiOn. The pest originated in Venezuela. This pest can disable some anti-virus programs. It affects such operating systems as Windows 95, Windows 98, Windows NT, Windows 2000, Windows XP and Windows Me. The users of Windows 3.x, Macintosh, OS/2, UNIX and Linux operating systems are immune. Threat type: RAT - Remote Administration Tool (RAT) is a software application which provides an attacker with the capability to control your computer system remotely whenever you are online. The attacker can perform operations such as programs and/or files adding/deleting, files transfers, capturing screenshot, etc. Attacker may use captured computer for different personal needs such as to send malicious attacks. Advice: Remove This is a very high risk threat and should be removed immediately as to prevent harm to your computer or your privacy. Detection: SpyNoMore detects RAT/Massaker: Yes Threat risk: High Risk Very dangerous malware. Can log user's keyboard activity and take snapshots of the user's screen. Uses stealth installation and removal is very difficult. Category includes spyware programs, adware programs and trojans. Symptoms: Running Process Signatures: N/A File Signatures: %WINDOWS%\system\winboot.exe Registered Dll (Dynamic Link Library) Signatures: N/A Folder Signatures: N/A Registry Signatures: N/A SpyNoMore Collected Residual File Signatures: N/A
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||