Home Malware Programs Remote Administration Tools Near Mohists

Near Mohists

Posted: March 28, 2006

A Remote Administration Tool is a special kind of hacker malware, used for remote access and control of other people's PCs. The attacker infects the PC via the e-mail or File and Print Sharing. A "server" allows him to connect via a "client" on his own machine. The functions of a RAT may vary, depending on the needs of the hacker. Some RATs can't really harm your PC and the only purpose they were made for is hooliganism. But some versions can steal vital information, remove files and even crash your computer. This RAT was created using Visual Basic applicationming language. The origination date is January 2003. It was written by a Chinese hacker called Near Mohists. This pest affects such operating computers as Windows 95/98/ME/2000. The interface of the application is written in Chinese.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 sysraty.exe
    2 sysrtay.lgc

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionunservicessystemtyunsysjinbHKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionunsysportHKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionunsystemtyHKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversion
Loading...