Remove DuckToy. Description and removal instructions

 
Title: DuckToy

Type: Remote Administration Tools
Severity scale:DuckToy severity is 57  (57 / 100)
 
DuckToy is a big RAT virus family. Several versions appeared from March
2002 to December 2002. The author is a hacker called Gumi. The
origination place is Spain. The virus is vritten is Delphi programming
language. The attacker infects the machine with a "server" program can
control it, using a "client" on his computer. Once embedded, the virus
opens a default port 29559 and 59211 and awaits hacker commands. This
pest affects Windows 2000, Windows 95, Windows 98, Windows Me, Windows
NT and Windows XP operating systems. DOS, Linux, Macintosh, OS/2, UNIX
and Windows 3.x are immune to this pest.

From the publisher:

"+ Interface mejorada. + Compativilidad con Windows Xp. + Actualizacion
desde la misma ventana del chat. + La victima puede elegir el nick que
quiera. + Icono del server canviado. + REduccion atraves de UPX del
server en solo 260kb. + Indetectavilidad por parte de los antivirus
(28-06-02). + Problemas con el FTP solucionados y nueva interface. +
Evitado el cerrar el server, atraves de Alt + F4. + ... Ducktoy 1.1.1:
+ Porblema del Alt+F4 y el no poder apagar el sistema solucionado. +
Problema de la lectura de las unidades por el FTP solucionado. + El
chat se puede actualizar todas las veces que se quiera, sin que al
server el boton se le reduzca. + En el aviso atraves del ICQ, ya avisa
de quien esa IP, diciendo el Host y nombre de usuario."


DuckToy properties:
• Allows remote user connection
• Hides from the user
• Stays resident in background

Automatic DuckToy removal:

remover for DuckToy

DuckToy manual removal:

Kill processes:
ducktoy 1.1.1.exe, ducktoy, 1.2.exe, ducktoy.exe, editor, del, server.exe, edit-server.exe, server.exe, [system, root]\\explorer, .exe, [system, root]\\system36.exe
Delete files:
ducktoy 1.1.1.exe, ducktoy 1.2.exe, ducktoy.exe, editor del server.exe, edit-server.exe, novedades.txt, server.exe, [system root]\\explorer .exe, [system root]\\system36.exe, upx leeme.txt

Other programs to remove DuckToy:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 20/03/05
Information updated: 20/03/05

Additional resources related to DuckToy:

Attention: If you know or you have a website or page about DuckToy removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about DuckToy parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: