Skip to main content

Asylum

Classification

Category:

Malware

Aliases:

  • Asylum
  • Backdoor.Asylum

Summary

Asylum is a simple backdoor that works on Windows 9x/ME, NT/2000. The backdoor is located in the windows directory and called 'winmp32.exe'. When run it installs itself and sends a notification to the author about the infected machine using ICQ web interface. The service then runs on TCP port 81 and accessible from anywhere if the machine has direct Internet connection.

Removal

Technical Details

It supports the following commands:

- password authentication (required before the other commands) - remove the backdoor from the system - reboot the machine - print Windows directory - print Windows system directory - upload a file to the machine - run a program on the machine

For installation it has many ways of modifying the system. It chooses from them using internal variables set by the author.

It can create keys under

'[HKLM]\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SystemAdministration' '[HKLM]\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\SystemAdministration'

Other way is to modify win.ini to look like this:

[Windows] load=winmp32.exe run=winmp3.exe [boot] shell=explorer.exe winmp32.exe

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.