Home Malware Programs Remote Administration Tools DeepThroat

DeepThroat

Posted: March 28, 2006

DeepThroat is a large RAT virus family. As the number of the version grows, so does the ammount of functions and the damage, that can be done by this application. It can be classified as a very dangerous virus, because it cal log keys in real time and steal passwords. It also provides the attacker a full control over the infected computer. Newer versions appeared from February 1998 to November 2002. The author is a hacker called Cold. The applicationming language is Delphi, Compressed with NeoLite.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 _l0t.txt
    2 amsgb.dfm
    3 amsgb.pas
    4 bugfixs.txt
    5 client.ini
    6 confstub2.dll
    7 dialup.pas
    8 diskinfo.pas
    9 dtv3 client.exe
    10 dtv3.1
    11 dtv31-lite-client.exe
    12 dtv31-lite-client.ini
    13 filefind.pas
    14 findproc.pas
    15 ident.pas
    16 ircclient.pas
    17 keyspy.pas
    18 klayouts.inc
    19 online.pas
    20 ras_api32.pas
    21 rascomp32.pas
    22 readme.html
    23 readme.rtf
    24 readme.txt
    25 remotecontrol.exe
    26 sendkeys.pas
    27 showpictureunit.dfm
    28 showpictureunit.pas
    29 smarthacksecurity.txt
    30 stealth.pas
    31 systempatch.dof
    32 systempatch.dpr
    33 systempatch.exe
    34 systempatch.res
    35 toolhelp32.pas
    36 udp.dfm
    37 udp.pas
    38 unit1.dfm
    39 windowlist.pas
    40 winperf.pas
    41 wsocket.dcu

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionunsystemdll32

Related Posts

Loading...