Y3K RAT


Name: Y3K RAT
Aliases: Backdoor.Explorer32, Explorer32, Backdoor.Y3KRat,
Ports: 5802, 5880, 5882, 5882 (UDP), 5888, 5888 (UDP), 5889, 6667 (ports can be changed)
Files: Y3k_rat1.0.zip - 578,582 bytes Y3k_rat1.1.zip - 612,354 bytes Y3k_rat1.2.zip - 864,472 bytes Y3k_rat1.3.zip - 933,015 bytes Y3k_rat1.4.zip - 971,864 bytes Y3k_rat1.4b.zip - 962,584 bytes Y3k_rat1.5.zip - 1,085,674 bytes Y3k_rat1.6.zip - 1,131,412 bytes Server.exe - 287,232 bytes Server.exe - 290,816 bytes Server.exe - 302,848 bytes Server.exe - 303,616 bytes Server.exe - 323,072 bytes Server.exe - 328,448 bytes Server.exe - 332,800 bytes Y3k server.exe - 296,960 bytes Y3k rat 1.0.exe - 304,128 bytes Y3k rat 1.1.exe - 319,488 bytes Y3k rat 1.2.exe - 384,000 bytes Y3k rat 1.3.exe - 399,872 bytes Y3k rat 1.4.exe - 396,800 bytes Y3k rat 1.6.exe - 440,320 bytes Y3k14b.exe - 397,312 bytes Client.exe - 518,144 bytes Edit server.exe - 200,704 bytes Edit server.exe - 207,360 bytes Edit server.exe - 218,624 bytes Server editor.exe - 206,848 bytes Server builder.exe - 617,472 bytes Rundll.exe - Y3k.dll - 44,032 bytes Y3kicons.dll - 311,840 bytes Advapi32.exe - [296 kb]Icqmapi.dll - 58,368 bytes Online.wav - 14,093 bytes Dcomcnofg.exe - 328,448 bytes Nvarch16.exe - 296,960 bytes Unpacking16.dll -
Created: May 2000
Requires:
Actions: Anti-protection trojan / Remote Access / Steals pwasswords / ICQ trojan / IP sniffer / AIM trojan / MSN trojan / Downloading trojan / / Eavesdropper / EXE binder / SMTP server / Destructive trojan
Registers: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\
HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Run\
Notes: Works on Windows 95, 98, ME, NT, 2000 and XP, together with ICQ, MS MSN Messenger and AOL´s AIM. Have great problems with registrating on Windows NT.
Country: written in Greece
Program: Written in Delphi.

© Copyright von Braun Consultants. This information may include technical inaccuracies or typographical errors. If you have any questions or further information about the actual trojan above, please contact Joakim von Braun at <joakim.von.braun@risab.se>