Virus name (in Chinese):
Virus alias:
Threat Level: ★☆☆☆☆
Virus type: Trojan Horse program
Virus Length: 1412608
Impact System: WIN9X\WINME\WINNT\WIN2000\WINXP\WIN2003
Virus behavior:
This is a Trojan horse program, it will read some of the user system configuration information, and create a backdoor, connect the virus author designated remote server, waiting for hackers to connect.
Release the following files on disk:
C:\WINDOWS\Nt_File_Temp\
C:\WINDOWS\Nt_File_Temp\list.bmp
The following files were deleted on disk:
C:\WINDOWS\Nt_File_Temp\list.bmp
The virus will connect to the URL specified by the author:
The virus downloads files from Http://**3389.*****.txt to the local computer C:\WINDOWS\Nt_File_Temp\list.bmp
Domain Name: "513389.***** Port: (TCP)
513389.*****.txt
The following processes were created in the system:
The virus creates a mutex mick_download_mutex that prevents repeated running