Hackarmy Computer Virus
Also known as: Backdoor.Hackarmy.a-i, BackDoor-AZV, Troj/Hackarmy-A, W32/Rawbot.worm
Mass postings (about Nick Berg, Osama bin Laden or Schwarzenegger) to thousands of different newsgroups were done to 'seed' the Trojan as far as possible. Once the hacker has access they can do whatever they like: steal confidential information, tamper with or delete data, send spam, launch denial of service attacks.
Troj/Hackarmy-A is an IRC backdoor Trojan that copies itself into the Windows system folder as win32server.scr or win32server.exe and sets the registry entry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ Winsock32driver = wn32server.scr HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ Winsock32driver = win32server.exe
|