Backdoor.Tumag allows unauthorized remote access to an infected computer. By default, the backdoor listens on TCP port 9010.
When Backdoor.Tumag is executed, it performs the following actions:
Copies itself as:
%System%\dcemgr.exe
%System%\dcemgr2.exe
Creates the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\DCE
to keep track of the infection's progress.
Connects to dns2010.vicp.net or 218.242.161.151 on port 9002 to notify the author of the backdoor.
Opens a backdoor on TCP port 9010 and listens for commands from the attacker.
The backdoor can perform the following default actions:
- Update itself
- Take a screenshot
- Provide system information
- Create files
- Execute programs
Manual removal:
Navigate to the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
and delete the value: "DCE Manager"="%System%\dcemgr.exe"
Removal: dcemgr.exe is removed by RegRun.
Read more... Removal instructions...
Recommended software:
UnHackMe - easy removal Rootkits/Adware/Spyware.
http://www.unhackme.com
RegRun Security Suite - removal and protection.
http://www.regrun.com
RegRun Reanimator - free removal tool.
greatis.com/reanimator
RegRun - User's Choice
Vista Programs - full info...
What is hidden in MSDN?
.NET Secrets Revealed
Why software developers prefer Win32.FreeTechSecrets.com?
All Unix Manuals in Alphabetical Order
C# controls for .NET in 3 simple steps.
Constantly updated. Last update:
May 12 2008
Interesting information about Vista programs...
Need consultation?
Would you like to add your opinion?