Default Block Backdoor/ SubSeven Trojan Horse
Moderator: S2k Moderators
Default Block Backdoor/ SubSeven Trojan Horse
Norton Internet 2003 caught this and stopped it. Visual Tracking showed it came from Los Angeles.Domain name AOL. What do I need to do with this info and what is it?
Debbie
Debbie
0 likes
- mf_dolphin
- Category 5
- Posts: 17758
- Age: 68
- Joined: Tue Oct 08, 2002 2:05 pm
- Location: St Petersburg, FL
- Contact:
Here's some info on the virus:
CHARACTERISTICS
SubSeven is a trojan similar to Back Orifice. Unlike Back Orifice and NetBus, SubSeven does not claim to be a legitimate administration tool. These types of programs (sometimes called "Backdoors" or "Remote Access Trojans") consist of a trojan server and a client program. The server is usually received as an e-mail attachment which installs itself onto the system when run. It may display a fake error message in order to make it seem that the program failed to execute.
When installed, someone can use the client program to connect from another machine and control different parts of the system, ranging from opening and closing the CD drive to modifying the registry, uploading files, and rebooting. It can also take screen shots, monitor keystrokes, and steal passwords from the infected machine. The server can also be set up to send an ICQ, IRC or e-mail message to notify someone of the computer being open to attack.
Compared to earlier versions SubSeven 22 has some new features like proxy support, extended notification capabilities, network sniffing, enhanced distributed denial of service attack (DDoS) capabilities and an open architecture, allowing to expand the base functionality by downloadable plugins.
CHARACTERISTICS
SubSeven is a trojan similar to Back Orifice. Unlike Back Orifice and NetBus, SubSeven does not claim to be a legitimate administration tool. These types of programs (sometimes called "Backdoors" or "Remote Access Trojans") consist of a trojan server and a client program. The server is usually received as an e-mail attachment which installs itself onto the system when run. It may display a fake error message in order to make it seem that the program failed to execute.
When installed, someone can use the client program to connect from another machine and control different parts of the system, ranging from opening and closing the CD drive to modifying the registry, uploading files, and rebooting. It can also take screen shots, monitor keystrokes, and steal passwords from the infected machine. The server can also be set up to send an ICQ, IRC or e-mail message to notify someone of the computer being open to attack.
Compared to earlier versions SubSeven 22 has some new features like proxy support, extended notification capabilities, network sniffing, enhanced distributed denial of service attack (DDoS) capabilities and an open architecture, allowing to expand the base functionality by downloadable plugins.
0 likes
- mf_dolphin
- Category 5
- Posts: 17758
- Age: 68
- Joined: Tue Oct 08, 2002 2:05 pm
- Location: St Petersburg, FL
- Contact:
Marshall maybe you can help me with this one. Yesterday I cleared my explorer cache and defragged my drive. I play Word Whomp in Pogo all the time and had NO problems with the games loading until after I did all of that. I contacted tech support at Pogo and they told me they are having no games loading problems. Did I do something wrong?
0 likes
- mf_dolphin
- Category 5
- Posts: 17758
- Age: 68
- Joined: Tue Oct 08, 2002 2:05 pm
- Location: St Petersburg, FL
- Contact:
- streetsoldier
- Retired Staff
- Posts: 9705
- Joined: Wed Feb 05, 2003 11:33 pm
- Location: Under the rainbow
Linda, I played "Word Whomp" on "Pogo Games" several months ago. I have been interested in "First Class Solitaire" more often for awhile... however I haven't been able to access; (I even tried "Word Whomp" once the last few days, too). It keeps loading, so I am unable to access the game(s) to play.
Marshall, I have cleaned the cache and cleaned my coookies and have still been having the same problem.
This has been going on for about two weeks.
Marshall, I have cleaned the cache and cleaned my coookies and have still been having the same problem.
This has been going on for about two weeks.
0 likes
Tom... I am still having the same problem. I have never had this problem before though. The tech support at Pogo is telling me I need to install or update my Java for Internet Explorer. I am frowning on that decision. So I am going to take my hard drive to a good friend this evening so he can take a look at it. I will let you know what he finds. Your problem and mine could be the same.
0 likes
- mf_dolphin
- Category 5
- Posts: 17758
- Age: 68
- Joined: Tue Oct 08, 2002 2:05 pm
- Location: St Petersburg, FL
- Contact:
Tom... I went ahead and installed the Java update for internet explorer and BOOM my games now load.
Here is the address for the Java update.
http://java.sun.com/getjava/download/html
It has downloads for internet explorer, netscape etc. Have any problems let me know.
Thanks for all your help Marshall.
Here is the address for the Java update.
http://java.sun.com/getjava/download/html
It has downloads for internet explorer, netscape etc. Have any problems let me know.
Thanks for all your help Marshall.
0 likes
Who is online
Users browsing this forum: No registered users and 7 guests