Search:  In

 RedShell 1.0 - Description


 Browse by name

 
 | misc | a | b | c | d | e | f | g | h | i | j | k | l | m | n | o | p | q | r | s | t | u | v | w | x | y | z |

Description:
RedShell is a light (15k) backdoor that is capable of spawning a shell on a remote computer, allowing a user the ability to connect (via Telnet, NC. etc) up to the remote computer, [port 1337], and execute any commands they wish. Installation: Put WINSYS32.EXE into the Windows/System32 folder of your victims computer and execute. Uninstallation: Kill the WINSYS32.EXE process, Delete WINSYS32.EXE from the Windows/System32 folder and to remove the service, start Regedit and delete: HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesWINSYS32


Alias:
Backdoor Program [Panda]
Backdoor.Small.n
Backdoor/Cigivip.10 [Computer Associates]

Category:
Backdoor

Automatic Removal: Most effective removal tool is: Easy SpyRemover

Manual Removal:



Stop Runnin Processes:
winsys32.exe



Unregister DLLs:
Unknown


Clean Registry:
Unknown


Remove Files:
readme.txt
winsys32.exe

   


Latest Spyware Threats
    Rapid Antivirus
    RealAV
    PC MightyMax
    Internet Antivirus Pro
    Expert Antivirus 2009
    Spy Guard 2008
    Spyware Guard 2009
    MicroAV Security Center
    Sagipsul
    Comodo Trust Toolbar
    XP Antispyware 2009
    Antivirus 2010



Copyright © PcRepairCentral, 2005.