NetDefend IPS
IPS Advisories
NetDefend
Anti-Virus
Anti-Virus Advisories
NetDefend Web Content Filtering
NetDefend IP Reputation
NetDefend Update Center
IPS History
Sep 21, 2020
Sep 14, 2020
Sep 07, 2020
Aug 31, 2020
Aug 24, 2020
Anti-Virus History
Aug 19, 2020
Aug 05, 2020
Aug 04, 2020
Jul 10, 2020
Jun 11, 2020







Home > NetDefend Live > NetDefend IPS Service
NetDefend IPS Service
Print
Advisory ID
2010
Name
Dark Connection Inside backdoor
IPS Signature
Maintenance IPS Signature
IPS Group
FROM / INT / ATTACK / RESPONSES
Issued
Sep 08, 1999
Description
Dark Connection Inside, also known as Backdoor.DCI.12 and Dark Connection, is a backdoor Trojan affecting Microsoft Windows operating systems. The server attempts to open a port, typically TCP port 666, to allow the client system to connect.
The client has the ability to emulate the server when it is running. This can be used to trick other hackers, and all commands sent to the emulated server are shown on the local client.
Affected Application
Microsoft Corporation: Windows Any version
Solution
Open up regedit (go to start, then run and type regedit then hit ok) the follow this path:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
- And look for the following value "DirectX 3D Service" right click on this value and choose delete.
- Now follow this path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- And look for the following value "MSGSRV16.EXE" and "Service386Shell" right click on these values and choose delete.
Refferences
http://xforce.iss.net/xforce/xfdb/15161
http://www.justkiwi.com/tairua/antitrojan/trojans/Darkconnection%201.2.htm
http://www.glocksoft.com/trojan_list/Dark_Connection_Inside.htm
http://www.simovits.com/trojans/tr_data/y787.html
Enter your details in the box below to receive an email each time we post a new issue of our newsletter.







Sep 29, 2020