Port No | 11050 |
Service Name | Host Control |
RFC Doc | 0 |
Protocol | TCP |
Description | Works on Windows 95 and 98. Possibly also on NT. |
Reference Link | Host_Control |
Attack | Registers: HLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ HCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Files: Hc1.zip - 177,601 bytes Hc20.zip - 279,254 bytes Hostcontrol2.5.zip - 311,197 bytes Hc26.zip - 279,407 bytes Hc26binstall.zip - 2,007,989 bytes Hostcontrol2.7.zip - 2,949,143 bytes Hostcontrol_prof.zip - 179,119 bytes Regclean.exe - 89,600 bytes Setup.exe - 84,992 bytes Setup.exe - 89,088 bytes Setup.exe - 89,600 bytes Setup.exe - 95,744 bytes Host control client 26b.exe - 65,929 bytes Host control client 2.7.exe - 90,775 bytes Host control.exe - 129,536 bytes Host control.exe - 1,040,896 bytes Host control 20.exe - 107,008 bytes Host control 25.exe - 238,080 bytes Host control professional.exe - 251,904 bytes Server.exe - 132,178 bytes Servidor.exe - 253,674 bytes Dat.dat - 106,256 bytes Dat.dat - 108,336 bytes Setup.lst - 7,985 bytes Setup.lst - 8,246 bytes Temp.exe - Winkernel.exe - Dat.pkl - 108,336 bytes Dat1.tmp - 128,874 bytes Cinstall.com - 2,261 bytes Mswinsck.ocx - 62,242 bytes Mswinsck.ocx - 106,256 bytes Comdlg32.ocx - 66,358 bytes Comdlg32.ocx - 74,707 bytes Comdlg32.ocx - 128,784 bytes Regcle32.exe - Winsock.ocx - 74,664 bytes Ocxreg.bat - Msvbvm50.dll - 865,320 bytes St5unst.exe - 37,851 bytes Setup1.exe - 73,382 bytes Vb5stkit.dll - 16,458 bytes Stdole2.tlb- 7,136 bytes Oleaut32.dll - 323,508 bytes Olepro32.dll - 15,904 bytes Asycfilt.dll - 75,818 bytes Ctl3d32.dll - 15,600 bytes Comcat.dll - 10,146 bytes Tabctl32.ocx - 117,595 bytes Tabctl32.ocx - 128,482 bytes St5unst.log - Html.ocx - 87,983 bytes Axdist.exe - 831,922 bytes Actions: Remote Access / Destructive trojan / Virus dropper It copies itself to c:\recycled to avoid detection by some antivirus programs. |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.