Home Malware Programs Remote Administration Tools Anal FTP

Anal FTP

Posted: March 28, 2006

This simple to use hacker application, written in Assembly language, was designed as a FTP transfer tool, but it also includes an execute file function. It uses such stealth methods as "trojan" and "backdoor" to infect the PC and stay resident in the memory, without being found. The author is a hacker called stan. The virus originated in May 2002.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 analftp.exe
    2 analftp.obj
    3 analftpanalftp.asm
    4 commands.asm
    5 cprocs.asm
    6 dtpcommands.asm
    7 dtpconnections.asm
    8 editserver.asm
    9 editserver.exe
    10 editserver.obj
    11 icqnotifynew.asm
    12 icqnotifyold.asm
    13 install.asm
    14 make.bat
    15 readme.txt
    16 resource.inc
    17 rsrc.rc

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINEsoftwaremicrosoftactivesetupinstalledcomponentsanalftp
Loading...