Remove Insane TCP Backdoor. Description and removal instructions

 
Title: Insane TCP Backdoor

Type: Remote Administration Tools
Severity scale:Insane TCP Backdoor severity is 57  (57 / 100)
 
This RAT program uses the same basic principles that all RATs do: the victim's computer is infected with a server program, and the attacker can access it from a distant machine, using a client on his own machine. This pest allows the intruder to control the infected PC completely unnoticed, because it uses such stealth techniques as "backdoor" and "trojan". The infection is more likely to be performed via the e-mail. The author of this virus is a hacker called Insane. The pest originated in June 2000.

From the publisher:

"Features: - My first Win32 virus - Polymorphic. - Antiheuristics and EPO. Also works as good antidebugging feature against beginners (means lammers - Double encrypted. First decryptor resides in first section of victim. Second one,before virus code. - Selfpacking. Depends on victim, but sometimes compression could give 3.5 to 1 result (LZSS scheme - Per-process residency - Dosn't infect antiviruses (russian AVP' 'DrWeb only - filemask - Contains TCP backdoor Backdoor features 1. System info. Return system version,username,number of disks, . Upload' 'Execute Upload and execute file. After execution file is deleted. 3. Mass Download For example c windows pwl . Dir Directory listing 5. Backdoor shutdown (till next infected file run 6. Ability to upload plugins. - Infection not depends from attributes. - Windows directory infection. - Tested on Win95 OSR2,WinNT 4. ,Win2000,Win98 - completely workable. - Two infection methods 1. Standard add section . 2. Reloc residency (because it not used in PE Exe' . Possible it is not correct, but 100% works) - Some ready plugins applied. - MessageBox - remote message box. - Shutdowm- remote shutdown - Gateway - redirection of TCP connections."


Insane TCP Backdoor properties:
• Allows remote user connection
• Hides from the user
• Stays resident in background

Automatic Insane TCP Backdoor removal:

remover for Insane TCP Backdoor

Insane TCP Backdoor manual removal:

Kill processes:
fce07b0f.exe, gateway.exe, gl.exe, test.exe
Unregister DLLs:
39df5f5f.dll, shutdown.dll

Delete files:
39df5f5f.dll, fce07b0f.exe, gateway.c--, gateway.exe, gateway.rc, gl.c--, gl.exe, gl.rc, infect.inc, info.txt, msgb.asm, plugins.h--, plugins.inc, readme.txt, ripper.c--, shutdown.asm, shutdown.dll, tcp.inc, test.asm, test.exe, test.obj, uc.inc, win32.inc, wsmm.inc

Other programs to remove Insane TCP Backdoor:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 31/03/05
Information updated: 31/03/05

Additional resources related to Insane TCP Backdoor:

Attention: If you know or you have a website or page about Insane TCP Backdoor removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Insane TCP Backdoor parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: