Event ID - 146

Port No146
Service NameInfector
RFC Doc0
ProtocolTCP
DescriptionWorks on Windows 95, 98 and ME, together with ICQ.
Reference LinkInfector
AttackRegisters:
Does not register.

Files:
Fc.zip - 462,863 bytes Infector.zip - 95,103 bytes Infector.zip - 101,764 bytes Infector1.0.zip - 285,601 bytes Infector1.3.zip - 445,950 bytes Infector1.4.zip - 504,012 bytes Infector1.4.2.zip - 570,490 bytes Infector1.6.zip - 604,218 bytes Infector1.6a.zip - 661,515 bytes Infector1.6b.zip - 691,336 bytes Infector1.7c.zip - Infector_1.7_bonus.zip - Infector2.0.zip - 36,395 bytes Infector9.0.zip - 5,599 bytes Infector_v2.zip - 35,713 bytes Infector.exe - 18,929 bytes Infector.exe - 87,944 bytes Infector.exe - 184,832 bytes Infector.exe - 291,840 bytes File_id.exe - 3,632 bytes Client.exe - 174,080 bytes Client.exe - 178,176, bytes Client.exe - 294,912 bytes Client.exe - 333,824 bytes Server.exe - 120,320 bytes Server.exe - 293,888 bytes Server 1.6b_new.exe - 527,872 bytes Unpacked _server.exe - 299,008 bytes Unpacked_server.exe - 300,544 bytes Editsrv.exe - 114,688 bytes Editsrv.exe - 140,800 bytes Editsrv.exe - 233,984 bytes Editsrv.exe - 236,544 bytes Editserv.exe - 141,312 bytes Fc32.exe - 414,208 bytes Fc_1.6server_a.exe - 534,016 bytes Uhanfo.exe - 6,912 bytes Trojan.exe - D3x.drv - Setup.int - ??? bytes Msnapplication.exe - - 532,016 bytes

Actions:
Downloading trojan / Trojanizes EXE-files / Trojan droper / ICQ trojan
Alters System.ini. Trojanizes files and adds about 29k to the infected file. It may only be configuerad only when connected to the trojan server. The file "Setup.int " consists of all logged keys the user has pressed. The server is always distributed in a uncompresed version, so others can us any compresor of their choice. It also make the server harder to detect. Version 1.7 bonus is a recompiled version of 1.7 - the same trojan but with a different signature.

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.