Home Malware Programs Remote Administration Tools Lizards Tail 1.1

Lizards Tail 1.1

Posted: March 28, 2006

A Remote Administration Tool is a special kind of hacker malware, used for remote access and control of other people's PCs. The attacker infects the PC via the e-mail or File and Print Sharing. A "server" allows him to connect via a "client" on his own machine. The functions of a RAT may vary, depending on the needs of the hacker. Some RATs can't really harm your PC and the only purpose they were made for is hooliganism. But some versions can steal vital information, remove files and even crash your computer. It creates a "backdoor" in the security computer of the victim, allowing the intruder to connect completely unnoticed. This RAT tool originated in France in February 2002. The applicationming language is Delphi. It was created by a hacker called Marcel. The source of the application is included, so anyone, who knows Delphi can modify this pest, according to his needs. Warning: this pest includes a "keylogger". It logs all user's keystrokes and sends the collected information to the intruder.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 _lizard_s_tail.dcu
    2 _lizard_s_tail.dfm
    3 _lizard_s_tail.pas
    4 dxdlg.exe
    5 hlp.exe
    6 lizard_s_tail1.dof
    7 lizard_s_tail1.exe
    8 serveur_sans_le_jeu.exe
    9 unit2.dcu
    10 unit2.dfm
    11 unit2.pas
    12 unit3.dcu
    13 unit3.dfm
    14 unit3.pas
    15 unit4.dcu
    16 unit4.dfm
    17 unit5.dcu
    18 unit5.dfm
    19 unit5.pas

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionunhlp.exe
Loading...