AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
December 02, 2008, 12:42:29 PM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 4756 Members
Latest Member: Uobeley
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Windows-based Security Issues  |  Topic: Hacktool.Vanquish Hack Tool 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: Hacktool.Vanquish Hack Tool  (Read 1016 times)
Brad
SysAdmin
Tech Team
Hero Member
********
Offline Offline

Posts: 391



View Profile
Hacktool.Vanquish Hack Tool
« on: June 06, 2005, 12:40:51 AM »

Behavior
Hacktool.Vanquish is a tool that hides all files and folders with the string "vanquish" in their name.

Symptoms
The presence of one or more files detected as Hacktool.Vanquish.

Transmission
The hacktool arrives as an .exe and a .dll file that must be manually installed on the computer.

technical details
File names: vanquish.exe
vanquish.dll

REMOVAL INSTRUCTIONS
See: http://securityresponse.symantec.com/avcenter/venc/data/hacktool.vanquish.html

When Hacktool.Vanquish runs, it does the following:

   1. Creates the mutex "VRTLogMutex".

   2. Adds itself as the following service:

      Service Name: Vanquish
      Service Display Name: Vanquish Autoloader v0.1 beta10

   3. Injects vanquish.dll into all processes.

      Note: The hacktool will not inject the module into processes whose files are hidden, nor does it create and use its own hidden folder.

   4. Hides all files and folders that have the string "vanquish" in their name.

   5. Creates the file C:\vanquish.log.
Logged

Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Windows-based Security Issues  |  Topic: Hacktool.Vanquish Hack Tool « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!