Fictional Daemon

Fictional Daemon is a remote control that can remotely control the user s PC. It is not harmful unless installed and used without the knowledge of the computer user or network administrator.

General information:

Malware Name: Fictional Daemon
Malware Type: Remote Control
Company Name: Patrick van Venetiën
Company URL: http://www.fictional.net/
Threat Level: Elevated Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

Patrick van Venetiën provides you the software cheapest and most complete daemon around for Windows 95/98/Me and WindowsNT/2K/XP. Remote control your computer by the network/internet with a telnet client. (FTP, shutdown/reboot, execute, schedule commands etc.

Spyware Description:

Fictional Daemon is a remote control that can remotely control the user s PC. It is not harmful unless installed and used without the knowledge of the computer user or network administrator.

Characteristics/Symptoms:

    -> It can remotely control the user s PC. -> It is not harmful unless installed and used without the knowledge of the computer user or network administrator.

Additional information might be found here:

google Search at Google for Fictional Daemon
bing Search at Bing for Fictional Daemon
yahoo Search at Yahoo for Fictional Daemon

Processes Running:

fd.exe

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\FDaemon\logs\log1.txt 6 Text Document
C:\Program Files\FDaemon\offline.htm 404 HTM File
C:\Program Files\FDaemon\users\dummydir.txt 6 Text Document

Folder information Created after Installation:

Folder Location
C:\Documents and Settings\All Users\Start Menu\Programs\Fictiona
C:\Program Files\FDaemon\user

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_CURRENT_USER \Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Fictional
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Fictional Daemon 4.4_is1
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Fictional Daemon 4.4_is1 Changed