Computing.Net > Forums > Security and Virus > Sub7 - BO2k

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Sub7 - BO2k

Reply to Message Icon

Name: SiiLV3R
Date: June 1, 2002 at 08:22:15 Pacific
Comment:

if you read n e hackers mags or ne thing of the sort you will know where i am going with this. someone was able to get BO2K (back orifice 2000 v. 2.1.4 for those who care) and subseven on my comp. i have removed the *.exe file but my msdos.exe is still corrupted. does n e one know how i can fix that without having to find my original cd-rom for win98se? if so contact me at txfasho@aol.com



Sponsored Link
Ads by Google

Response Number 1
Name: murve
Date: June 1, 2002 at 12:11:55 Pacific
Reply:

hi siilv3r,
here's some info on Back door 2, B.O.2k and Sub 7. for more info go to www.thepublicworks.com security section
click on Dalantec, Trojan Removal, and Simovits Consulting, you may also want to download from wilders.org a free 30 day trial of Trojan Hunter anti-trojan it will remove all trojans from your puter.

Backdoor2- Go to the HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ key. Look for an entry named Notepad that has a value of C:\Windows\Notpa.exe /o=yes If it exists, delete this entry then delete Notpa.exe from C:\Windows

Back Orifice- Most popular trojan program. To remove the default trojan, go to:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices in the registry. If you see an entry titled Default, with a value of .exe, delete it and reboot the machine. Do a search on your hard drive for a file called exe~1 and delete it.

Back Orifice 2000- Best defeated with a Virus scanner. Default version installs UMGR32.exe in the System directory. Highly configurable trojan, can be renamed easily.

SubSeven- Allows attacker to run 113 commands on your machine, essentially a hackers PCAnywhere to your box, though with less ability. Command files often renamed, though default to the Windows directory with names: SERVER.EXE, KERNEL16.DL, RUNDLL16.COM, SYSTEMTRAYICON!.EXE, WINDOS.exe or WINDOW.exe. The file WATCHING.DLL may be installed into the System directory. Registry changes calling the executable will be detectable in the Run or RunServices key. May also be called by System.ini or Win.ini.
good luck and cheers,
murve


0

Response Number 2
Name: marc
Date: July 11, 2002 at 13:45:18 Pacific
Reply:

whenever infected like this... just nuke 'n' pave and re-install.


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Sub7 - BO2k

Backdoor, Sub7! Grrrrrrrrrrrrrrr... www.computing.net/answers/security/backdoor-sub7-grrrrrrrrrrrrrrr/3687.html

sub7 's help please www.computing.net/answers/security/sub7-s-help-please/59.html

PC infected by sub7 trojan www.computing.net/answers/security/pc-infected-by-sub7-trojan/14751.html