Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
if you read n e hackers mags or ne thing of the sort you will know where i am going with this. someone was able to get BO2K (back orifice 2000 v. 2.1.4 for those who care) and subseven on my comp. i have removed the *.exe file but my msdos.exe is still corrupted. does n e one know how i can fix that without having to find my original cd-rom for win98se? if so contact me at txfasho@aol.com

hi siilv3r,
here's some info on Back door 2, B.O.2k and Sub 7. for more info go to www.thepublicworks.com security section
click on Dalantec, Trojan Removal, and Simovits Consulting, you may also want to download from wilders.org a free 30 day trial of Trojan Hunter anti-trojan it will remove all trojans from your puter.Backdoor2- Go to the HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ key. Look for an entry named Notepad that has a value of C:\Windows\Notpa.exe /o=yes If it exists, delete this entry then delete Notpa.exe from C:\Windows
Back Orifice- Most popular trojan program. To remove the default trojan, go to:HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices in the registry. If you see an entry titled Default, with a value of .exe, delete it and reboot the machine. Do a search on your hard drive for a file called exe~1 and delete it.
Back Orifice 2000- Best defeated with a Virus scanner. Default version installs UMGR32.exe in the System directory. Highly configurable trojan, can be renamed easily.
SubSeven- Allows attacker to run 113 commands on your machine, essentially a hackers PCAnywhere to your box, though with less ability. Command files often renamed, though default to the Windows directory with names: SERVER.EXE, KERNEL16.DL, RUNDLL16.COM, SYSTEMTRAYICON!.EXE, WINDOS.exe or WINDOW.exe. The file WATCHING.DLL may be installed into the System directory. Registry changes calling the executable will be detectable in the Run or RunServices key. May also be called by System.ini or Win.ini.
good luck and cheers,
murve

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |