Name: 2000 Cracks

 

Main: 2000cracks.exe, 200cracks.exe (can be either) 488kbs

 

Keys:  Win.ini Key:  load=closew     Under: [windows]

 

Version: NA (its the only one)

 

Type: file server (ftp)

 

Port/s used: 6776

 

Files:  Instll.bat, AJOUT.INI, closew.bat

 

Modifies:    win.ini; makes a back up called win.ori

 

Aliases:     none

 

Behaviour: This trojan opens up ftp server on the infected system on port 6776, this server is not passworded and has full read /write access

 

Removal: Open up win.ini (click on start, then go to search and look for win.ini double click on it) and look for closew.bat and delete that key.

Reboot your computer and then find the following files (use search again) and delete any found instances JOUT.INI, closew.bat and Instll.bat

 

Special: This file is hidden in what is supposed to be a program full of cracks (reverse engineered software patches created to make demo or shareware programs full version)

 

Author: N.A.

 

Notes: If you are infected with this trojan it is very important that you remove it as quickly as you can, the file server it opens will allow hackers to upload more sophisticated and powerful trojans and take complete control of your system.