Trojan.Diagcfg

Risk Level 1: Very Low

Discovered:
July 19, 2001
Updated:
February 13, 2007 11:56:26 AM
Type:
Trojan Horse

This Trojan modifies the registry so that it loads whenever Windows is started. It listens on port 6967 for commands. It sends email to its creator with information about the computer's IP address and connected hosts. If the program is run again while it is already running, it displays the message:

This program is part of the system and can not be run separately.

Antivirus Protection Dates

  • Initial Rapid Release version July 19, 2001
  • Latest Rapid Release version August 20, 2008 revision 017
  • Initial Daily Certified version July 19, 2001
  • Latest Daily Certified version August 20, 2008 revision 016
  • Initial Weekly Certified release date pending
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Easy

Damage

  • Damage Level: Low

Distribution

  • Distribution Level: Low
Writeup By: Jimmy Shah

Search Threats

Search by name

Example: W32.Beagle.AG@mm
ThreatCon Widget
Internet Security Threat Report, Volume 16
Symantec DeepSight Screensaver