 |
|
UDP_Matrix 2.0 Client connect
|
| |
Code:
p356
Severity: Warning
Description: Matrix is a Trojan Horse offering the attacker the ability to upload
files to, and download files from the victim host.
Impact:
Possible theft of data and control of the targeted machine leading to a
compromise of all resources the machine is connected to.
Corrective: Edit the system registry to remove the extra keys or restore a
previously known good copy of the registry.
Affected registry keys are:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Registry keys added
Wincfg.exe =":\WINDOWS\Wincfg.exe"
A reboot of the infected machine is recommended.
--
Contributors:
Original rule written by Max Vision
Sourcefire Research Team
Nigel Houghton
|