Home Malware Programs Remote Administration Tools NeoArk

NeoArk

Posted: March 28, 2006

This application was designed for illegal controlling of other people's PCs. The hacker infects the victim's machine via the e-mail or File and Print Sharing with a "server" application. He can later access the infected machine via a "client". The functions of a RAT may vary, depending on the needs of the hacker. Some may just do nasty things, while the user is working. Other can steal vital information and remove files. Several variants of this RAT appeared in the internet from November 2000 to January 2004. The pest was written in Visual Basic applicationming language. The author is a German hacker called THa_imaX.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 backdoor.neoark.21.exe
    2 neoark.exe
    3 neoarkserver.exe
    4 readme.txt

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionunservicesemmdriver
Loading...