Name:
2000 Cracks
Main:
2000cracks.exe, 200cracks.exe (can be either) 488kbs
Keys: Win.ini Key: load=closew Under:
[windows]
Version:
NA (its the only one)
Type:
file server (ftp)
Port/s used:
6776
Files: Instll.bat, AJOUT.INI, closew.bat
Aliases: none
Behaviour:
This trojan opens up ftp server on the infected system on port 6776, this
server is not passworded and has full read /write access
Removal:
Open up win.ini (click on start, then go to search and look for win.ini double
click on it) and look for closew.bat and delete that key.
Reboot
your computer and then find the following files (use search again) and delete
any found instances JOUT.INI, closew.bat and Instll.bat
Special:
This file is hidden in what is supposed to be a program full of cracks (reverse
engineered software patches created to make demo or shareware programs full
version)
Author:
N.A.
Notes:
If you are infected with this trojan it is very important that you remove it as
quickly as you can, the file server it opens will allow hackers to upload more
sophisticated and powerful trojans and take complete control of your system.