ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Network management Toolkit

New Back Orifice-like Trojan horse found

Bob Sullivan, MSNBC ZDNet.co.uk

Published: 28 May 1999 08:51 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Trojan horse arrives in a user's e-mail posing as a screen saver or game update, but once executed, it turns the victim's PC into an "open client." Then, a hacker can add, delete, move or execute files on the victim's computer at will from anywhere on the Internet. BackDoor-G is being sent out in spam mail, according to Sal Viveros, group marketing manager at Network Associates. The company discovered it Wednesday.

Updated versions of virus-scanning software, including Network Associates products, will detect BackDoor-G and clean it from a victim's system.

Such "remote administration tools" started to surface last year when Back Orifice was released by a group calling itself the Cult of the Dead Cow. NetBus, another such tool, has since been developed into a commercial product by its author. With both programs, a victim is tricked into executing an e-mail attachment which then opens his PC to remote connections via the Internet. Once a victim is infected, a hacker can do anything to a machine that the victim can -- included erasing all files or copying all files.

Such tools represent a dangerous blending of what might once have been considered relatively harmless pranks by virus writers and hackers, Viveros said: "We're seeing these types of malicious code attacks, which are trying to attack information directly or indirectly," he said. "Now we're seeming to blur the lines between malicious code attacks and [data] vulnerability."

BackDoor-G already has a variant -- a very similar Trojan named "Armageddon" was discovered in France Thursday morning. Several Network Associates clients opened the attachment and exposed their systems, Viveros said. But when the promised screen saver did not execute, they called the virus company.

He did not know immediately whether any data had been stolen but said he suspected there have been victims "because of the number of people we've had turn it in to us. We only get a small percentage." BackDoor-G installs three files on a user's system in the Windows and Windows/System directories. First, BackDoor-G.ldr is installed in the Windows folder and is used to load the main Trojan server. Then BackDoor-G.srv, the main Trojan that receives and executes commands, is installed in the Windows folder.

According to Network Associates, BackDoor-G.srv contains copies of Watching.dll or Lmdrk_33.dll. This DLL is copied into the WINDOWS/SYSTEM folder and is used by the Trojan server to monitor the Internet for connections from the client software. This file can be identified as BackDoor-G.dll. A configuration program called BackDoor-G.cfg is also dropped on the victim's machine.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
21 out of 80 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:












Related Jobs

Tooling Design Engineer - North West - Must look!

Huxley Associates Limited acts as an Employment Agency and an Employment Business) The work involves producing designs and detailed manufacturing ...

Huxley Associates - Recruitment Consultant Birmingham

Huxley Associates has an urgent requirement for hungry, sales motivated Recruitment Consultants, looking to prove themselves in an outstanding field ...

Solid Works Design Engineer - South Yorkshire

Huxley Associates Limited acts as an Employment Agency and an Employment Business) My client designs and manufactures special purpose machinery, so a ...

Featured Talkback

Could it be that ISP’s are making this out to be a bigger problem than it actually is? We’re a small country with an internet penetration of less than 60%, for every Youtuber there’s someone who only uses the internet to check their emails, more people surf on their mobile handsets than a few years ago. Surely things should even themselves up.

By: harpless

Read full story:
Unlimited-broadband offers to go 'within a year'

On The Road Blog

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment

Why do you need Portable password mana...

There are much more than 5, but I will start with these main points: 1. You are human... never mind, no one is perfect. 2. We live in modern world with its cons and pros 3. We... More

Post a comment

Over 10000 laptops are lost every week...

Yesterday article in PCWorld with reference to the Ponemon Institute survey claims close to 637,000 laptops lost in large US airports each year. The figure itself is amazing. But... More

Post a comment