Originally posted by Wietse
Maar, weet je zeker dat dit geen windows bestand is ipv een trojan?
This is a remote access trojan. It uses Microsoft MSN Messenger to access victim's machine. There are several variants of the trojan. One variant of the trojan copies itself to Windows directory as "Windll32.dll", and sets the following registry key:
* HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun
"Windll32" = C:WINDOWSWindll32.exe"
It also changes the start page of Internet Explorer. Other variants do not make these changes.
When run, the trojan launches the MSN Messenger executable in the background, and listens for various commands. Hackers can use MSN Messenger from another machine to send commands to victim's machine. It can perform the following operations on the victim's machine:
* chat anonymously
* start/stop mouse trembling
* open/close CD-ROM tray
* shut down computer
* minimize/maximize all windows
* re-arrange mouse buttons
* copy text to clipboard
* receive text from clipboard
* go to URL link
* set IE startup page
* flash Num/Caps/Scroll-locks
* put screen upside down
* set various status on MSN Messenger
* try to capture the password
* perform various tasks such as changing person's nickname, sending message to all contacts, etc.
Ik gebruik geen Windows, maar wel Google :)
Kijk eens naar de resultaten:
http://www.google.nl/search?q=windll32.exe&ie=UTF-8&oe=UTF-8&hl=nl&btnG=Google+zoeken&lr=