Home Malware Programs Remote Administration Tools Lithium

Lithium

Posted: March 28, 2006

This is a very dangerous Remote Administration Tool. It includes such functions as "password capture", "file manager", "screen capture:, etc. The attacker can steal all user passwords, take screenshots of user activity, download/upload files, stored in the infected PC. Lithium is a big RAT virus family. Versions appeared in the internet from December 2001 to October 2002. The pest is written in Delphi and visual C++ applicationming languages. The author of this pest is a hacker called Olympus. The pest also includes a "notifier" function. It means that the attacker gets notified via the e-mail once the pest infects some PC. Lithium Spyware is not at all related to Lithium Network Monitoring Platform.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 capture.lte
    2 cli_capture.dll
    3 default.ltf
    4 events.lsf
    5 example.lsf
    6 funstuff.lte
    7 history.txt
    8 lithium.exe
    9 lithiumserver.exe
    10 multimedia.lte
    11 multimedreadme.txt
    12 portscan.lte
    13 portscan2.txt
    14 pwinfo.lte
    15 readme.txt
    16 scan_readme.txt
    17 scripting.txt
    18 serveredit.exe
    19 serverlist.css
    20 serverlist.pl
    21 settings.lsf
    22 sin.exe
    23 srv_capture.dll
    24 srv_funstuff.dll
    25 srv_multimedia.dll
    26 srv_portscan.dll
    27 srv_pwinfo.dll
    28 uncompressed.txt
    29 uncompressedlithiumserver.exe
    30 unpacked 1.01b

Related Posts

Loading...