Home Malware Programs Remote Administration Tools Minicom (CS-Jami)

Minicom (CS-Jami)

Posted: March 28, 2006

This pest was written by a hacker called CS-Jami. The applicationming language is Visual C++. Several variants appeared from May 2000 to November 2003. The RAT affects such computers as Windows 95, 98, ME, NT 4.0, 2000 and XP. It was designed for illegal controlling of other people's PCs. The hacker infects the victim's machine via the e-mail or File and Print Sharing with a "server" application. He can later access the infected machine via a "client". The functions of a RAT may vary, depending on the needs of the hacker. Some may just do nasty things, while the user is working. Other can steal vital information and remove files.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 comnet.dll
    2 csjamisetup.exe
    3 dialup.htm
    4 faqs.htm
    5 help.htm
    6 hsetting.htm
    7 htips.htm
    8 htutor1.htm
    9 htutor2.htm
    10 htutor3.htm
    11 htutor4.htm
    12 htutor5.htm
    13 htutor6.htm
    14 inetfaqs.htm
    15 mcmm.dll
    16 mcrasint.dll
    17 minicom.exe
    18 minirem.exe
    19 myphone.exe
    20 ntcsjaminotify.dll
    21 ntmcdd.sys
    22 rasint.exe
    23 readme.txt
    24 setup.dat
    25 shutdown.exe
    26 startminirem.exe
    27 whatsnew.txt

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionunminirem
Loading...