Comments
SubSeven 1.8 now has 4 different
ways to infect. These infection methods can be choosen with the edit server.
SubSeven 1.8 has 3 different methods to get your IP and port to the hacker.
It can be configured to send ICQ messages, emails, or even go onto any
IRC server and give out your IP and port. This version can now view from
web cams.
Note: This is a trojan
that can be submitted to us for analysis. We can possibly determine
for you the password that was used and the ICQ UIN, Email or IRC channel
that was being notified. For more information on submitting trojan files
to us read here.
How To Remove
Quick fix: no
quick fix programs
Manual removal:
-
Remove the KERNEL32
key in the registry located at either HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
or HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices.
Which can be done with regedit or any other registry editing program.
-
Open the system.ini(Usually
c:\windows\system.ini) and change the key: shell=Explorer.exe
kerne132.dl under [boot] to shell=Explorer.exe, this can be done
with any text editing program.
-
Open the win.ini(Usually
c:\windows\win.ini) and remove the key: run=kerne132.dl
under [Windows], this can be done with any text editing program.
-
Reboot the computer or close the trojan.
-
Delete the trojan files kerne132.dl
in
the windows directory and MVOKH_32.dll located
in the Windows System directory(Usually c:\windows\system).
|