telnet.bat - Dangerous
telnet.bat
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
The backdoor server uses an mIRC client and client scripts to communicate with a remote attacker.
It also creates a FTP server.
Creates the following folder: %System%\CatRoot.
Creates some files in the CatRoot folder, such as: update.bat; ServUDaemon.exe; dcom.reg; patch.reg; tar.exe etc.
Connects to a remote IRC server and waits for commands.
Listens on TCP ports 3422 and 43958.
Manual removal:
Navigate to the key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
and delete the value: "Microsoft Office"="%system%\telnet.bat"
Delete the following keys:
HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\Security
HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\SystemManagementys2