Mosucker. How to remove? (Uninstall guide)

removal by Jake Doevan - - | Type: Remote Administration Tools

This RAT is presented as a tool that is supposed to help net administrators to control computers remotely. But a quick inspection of the vendor description leaves no doubt that this RAT tool can be used for illegal actions. It affects such operating systems as Windows 95/98/XP/ME/WinNT/2000. The pest was created by a German hacker called Krusty from a group called Inferno Industries. The pest is written in Visual Basic 6 and compressed with ASPack. Many versions appeared from December 1999 to March 2004. The infection peaked in such countries as Australia, France and the United States. Some versions also have the ability to disable Firewall protection on the infected PC.

From the publisher:

“MoSucker is a backdoor trojan, coded with Visual Basic 6. The server needs the vb6-runtime-dll msvbvm60.dll. It does no longer need any ocx-files (you can change this in the EditServer) This trojan is written for Windows 95/98, it wasn’t tested on other systems like 98se, NT and 2K, but it should work there, too. MoSucker is the best or one of the best trojans ever programmed with vb. Have fun with it!’
2.30: From the doc: ‘This list will kill (terminate) all well-known firewalls and Anti-Virus programs currently running on the victim’s system. It will NOT delete or currupt these programs, it will just stop them.’
3.0a: From the doc: ‘This list will kill (terminate) all well-known firewalls and Anti-Virus programs currently running on the victim’s system. It will NOT delete or currupt these programs, it will just stop them. Kills ZoneAlarm (Including Pro), LockDown, Norton AntiVirus, Trojan Check, Trojan First Aid Kit, MS Visual Studio Spy tools, Dr. Watson, RegEdit, The Cleaner, Trojan Defense Suit 3, Anti Trojan, Dr. Solomon, Norton Utilities, McAffee Virus scan, Kaspersky Anti Virus RegRun II, Tau Monitor, ANTS and AtGuard … and others’

MoSucker 3.0b – Released Nov. 20th 2002


1) MoSucker 3.0b servers are not compatible with the MoSucker 3.0a edit server. 2) If you get any runtime errors, execute Runtimes.exe in the runtimes folder. 3) Check the announcements in the forum for the latest public CGI locations. 4) The edit server cannot change the icon for servers that include the runtimes. Use reshacker or microangelo. Icon is 32×32 16 colors

Changes/bugfixes for 3.0b

– Modification of settings encryption for increased server security. – Edit server and client install runtimes if needed (since nobody can read). – MSN notification protocol error fixed. – MSN notification no longer gives visible error message when service is down. – Kill running system process checkbox error on reload fixed. – File exists routine for bound files fixed (bug rare) – Improved error handling in edit server. – Removed webdl.ocx dependancy.

MoSucker ErEbuS:

Ive packadged the mosucker trojan into a new trojan installer that compresses the file differently. This also installs the visual basic 6.0 runtimes with it. Copies file to system directory quietly and runs mosucker. Ofcourse, after it runs the mosucker server, the antivirus will pick it up. I leave this problem to you.

These are the attached server’s settings: port: 1037 (default) filename: wsvchost.exe deny local connections events: deleting/restoring of netstat and kills the threads of avs/fw melts the install


We might be affiliated with any product we recommend on the site.
do it now!
Reimage (remover) Happiness
Compatible with Microsoft Windows Compatible with OS X
What to do if failed?
If you failed to remove infection using Reimage, submit a question to our support team and provide as much details as possible.
Reimage is recommended to uninstall Mosucker. Free scanner allows you to check whether your PC is infected or not. If you need to remove malware, you have to purchase the licensed version of Reimage malware removal tool.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manual removal instructions below.

More information about this program can be found in Reimage review.

Mosucker manual removal:

Kill processes:
backdoor.mosucker.11.exe,createserver.exe,editserver 2.0.exe,editserver.exe,free pink.exe,mosucker 2.0.exe,mosucker.exe,,server.exe,server1.exe,server2.exe,server3.exe,server4.exe,server5.exe,skinmaker.exe,[system root]\jthh.exe,[system root]\msnetcfg.exe,[system root]\system\svr.exe,[system root]\temp\pkg310.exe,[system root]\temp\pkg332.exe,[system root]\temp\pkg3392.exe,[system root]\unin0686.exe,[system root]\vvuijoe.exe,v young.exe

Delete registry values:
HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled components{beuicvq-zpdev-zyk-oswoz-ipcjbgekjhf} HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled components{eengqgs-gdrfc-zzvzd-thmp-dnvpuihfkre} HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled components{hmcsqss-ejo-sdbyh-rcwb-ypenjkwjze} HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled components{mbubrwf-krfhc-cpg-qygw-lrjscpnsur} HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled components{rtemrsp-vhe-kgsoz-enjdg-tdtfhwtknffn}

Unregister DLLs:
moicons.dll,[system root]\buxyelbk.dll

Delete files:
1.stub 2.stub,3.stub,avkill_large.ini,avkill_small.ini,backdoor.mosucker.11.exe,bios killer plugin readme.txt,bios killer plugin v1.0.gui,bios_killer_plugin.msp,build.stub,createserver.exe,data.tag,editserver 2.0.exe,editserver.exe,fake login readme.txt,fake login.gui,fakelogin.msp,free pink.exe,front.jpg,fuck me!!!!!.vbs,get.cgi,help.chm,help+tutorial.chm,htm.cgi,infector readme.txt,infector.gui,infector.msp,moicons.dll,mosucker 2.0.exe,mosucker.chm,mosucker.exe,mosucker.ini,msn mass message readme.txt,msn message v2 readme.txt,msn message v2.gui,msn message.gui,msnmsgv2.msp,new default.title.gif,newfeatures.txt,,picture 26.jpg,pictures[1].txt,put.cgi,read me.txt,readme.txt,runtimes.txt,server.exe,server1.exe,server2.exe,server3.exe,server4.exe,server5.exe,setup.ini,setup.ins,skin.ini,skinmaker.exe,superclicks readme.txt,superclicks.gui,superclicks.msp,[system root]\buxyelbk.dll,[system root]\jthh.exe,[system root]\kernel32.txp{10},[system root]\msnetcfg.exe,[system root]\qirqgs.bin,[system root]\system\svr.exe,[system root]\temp\pkg310.exe,[system root]\temp\pkg332.exe,[system root]\temp\pkg3392.exe,[system root]\unin0686.exe,[system root]\vvuijoe.exe,[system root]\wesapygp.sys,[system root]\winexec32.dli,[system root]\xqwrmthm.sys,tapisvc.sys.txt,thumbs.db,v young.exe,webdl.ocx

