Subseven 2.1.4 DefCon 8


Name: Subseven 2.1.4 DefCon 8
Aliases: TROJ_SUB7.214DC8, TROJ_SUB7.382883,
Ports: 6667, 16959, 27374, (ports can be changed)
Files: Subseven2.1.4defcon8.zip - 1,414,240 bytes S721d.zip - Subseven.exe - 623,104 bytes Server.exe - 382,883 bytes Explorer.exe - 382,883 bytes Editserver.exe - 425,472 bytes Icqmapi.dll - 24,064 bytes Msrexe.exe - Sexxxymovie.mpeg.exe - - 623,104 bytes (compressed) - 1,945,600 bytes (uncompressed)
Created: July 2000
Requires:
Actions: Remote Access / Hacking tool / ICQ trojan
Alters Win.ini and System.ini. Generates several .exe-files withrandomly choosen names. The only real change in this version is that theserver was recompiled.
Versions: 2.1.4 DefCon 8,
Registers: HKEY_CLASSES_ROOT\exefile\shell\open\commandHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\
Notes: Works on Windows 95, 98 and NT, together with ICQ.
Country:
Program: 23

© Copyright von Braun Consultants. This information may include technical inaccuracies or typographical errors. If you have any questions or further information about the actual trojan above, please contact Joakim von Braun at <joakim.von.braun@risab.se>