 |
|
TCP_GateCrasher
|
| |
Code:
p20
Severity: Warning
Description: This event shows that a well-known Trojan Horse are running on the host, The GateCrasher backdoor is one of many backdoor programs that attackers can use to access your computer system without your knowledge or consent.
Impact:
With the GateCrasher 1.2 backdoor, an attacker can do the following:
start and stop an FTP server on your computer
restart your computer
chat with other users on the system
access files
access your system registry
Corrective: To remove the GateCrasher backdoor from your computer, follow these steps:
1. Using Regedit, find the HKLM\Software\Microsoft\Windows\CurrentVersion\Run registry key.
2. Find the registry entry named Command that has a data value of C:\Windows\system.exe.
3. Delete this registry entry.
4. Delete system.exe from the Windows system directory.
|