General information of BackDoor-EVH
Name: BackDoor-EVH (Free Scan)
Affected OS: Windows NT/2000/XP/Vista
Category: Backdoor
Risk level : risk level 3
Free Spyware Scan
Online computers are easy to be infected by various spyware
  • Fast spyware scanning and removal
  • 100% real-time protection
  • Antivirus/malware protection
Description

Once running, the server will attempt to open a HTTP connection to a specific web server (port 80), and post details of the victim machine to a script there in order to mail those details to the desired mailbox.
The posted details will typically include:

* victim IP address
* port number (for client connection)
* port number (for file uploading/downloading)
* system date and time

Also, the following characteristics were observed:

- enumerate logical drives
- get access to file system
- upload files
- download and execute additional malware
- delete/rename/move file
- enumerate and terminate choosen processes

This BackDoor will also answer the following commands:

SPLITTERFILE
CMDSHOW
CMDSTOP
CMDSTART
BROWSERDIR
UPLOAD
UPREQUEST
DIRECTDOWNLOAD
DOWNLOAD || FASTDOWNLOAD
DOWNREQUEST || FASTDOWNREQUEST
TERMINATEPROCESS
GETPROCESS
EXECUTE
RENAME
DEL
CREATEDIR
LOOKDIR
LOGOUT


Related Search
Other spyware: Spyware | Trojan | Backdoor | Worm | Adware | Rootkit | Downloader
.DLL Files:A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z
.EXE Files:A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z