Subseven Trojan
Description
    Review date: 01.01.2011
The latest versions of Windows includes TCP tunnel and advanced password recovery for Internet browsers. In today's application, most of antivirus can detect Sub7 program.

Subseven written in Delphi (also known as Backdoor-G and all of its variants) is the most well known Trojan backdoor application available.

You can download the setup-file of Sub7 from anywhere.

Some backdoor programs test the system and phone home to allow for future attacks. The best way to tell what version of SubSeven you are infected with is by running an updated antivirus program. It is similar to such malware as Back Orifice and Sub7 in that the suspect unknowingly downloads a backdoor through an email attatchment. Subseven tries to use ICQ, IRC and different e-mail accounts to notify the author that his victims are online. Sub7 can also make the victim's machine act as a zombie used in a DDoS attack to bring down some servers

Default ports used by some known trojan horses: port 31 Agent 31, Hackers Paradise, Masters Paradise
port 41 Deep Throat, Foreplay or Reduced Foreplay
port 110 ProMail trojan
port 113 Identd Invisible Deamon, Kazimas
port 559 (TCP/UDP)teedtap
port 605 Secret Service
port 1234 Ultors Trojan
port 1243 BackDoor-G, SubSeven , SubSeven Apocalypse, Tiles
port 1245 VooDoo Doll
port 1255 Scarab
port 12631 Whack Job
port 12754 Mstream
port 13000 Senna Spy Trojan Generator

The first version from SubSeven appeared in May 1999. SubSeven 2.0 is present since September 1999 and was written by an individual called MobMan. Apart from an extension of the characteristics above all the configuration options for the server installation were extended.

Besides, if the attack originated from a system that has a direct connection to your server or workstation with no gateway in between, then you can use the MAC address. The zip-file downloaded contained 3 executables: server.exe; sub7.exe and EditServer.exe. Moreover, the attack patterns for the NIDS snort can be used to recognize SubSeven network activity.

This trojan for the Windows platform is divided into two parts: a client tool and server software. The client and the server program, also again the Tool is contained for the modification of the actual server "EditServer" in the Orginal Zip file. Download an infected email attachment could be worse!

This trojan is the most popular and the most powerful Trojan Horse program available to the public.


Screenshots: Main Interface

When run, the backdoor copies itself to the Windows directory with the original name of the file it was run from or as SERVER.EXE, KERNEL16.DL, RUNDLL16.COM, SYSTEMTRAYICON!.EXE or WINDOW.EXE (names are different in different versions of SubSeven). Then it unpacks a single DLL file to the Windows System directory - WATCHING.DLL. This worm is also known as Backdoor.Subseven. This RAT or remote administration tool comprises two elements: the server (installed on the “target's” workstation; and a client used by the remote administrator.



After that the backdoor patches Windows Registry so that its main application will be run during every Windows bootup (Run or RunServices keys). Finally, it creates and modifies some other Registry keys. The backdoor can also install itself to the system by modifying either the WIN.INI or the SYSTEM.INI file.


Screenshot: Sub7 Victim Control Center - Remote Access Trojans

All the recent versions of SubSeven are supplied with a server configuration utility that allows it to customize server part capabilities - installation method, custom startup message, etc. This method was first introduced by the Back Orifice 2000 backdoor and it allows much more flexibility to backdoors. Please note that Troj/Sub7-2-13a is a backdoor package. Several versions of the package exist on the Internet, in 2009.

What can sub7 actually do?

  • SubSeven can do just about anything to anybody.
  • Internet downloads are slow
  • Monitor ALL of your online activity (purchases, chat, mail)
  • Strange dialog boxes appear
  • Restart Windows
  • Disable your antivirus or firewall
  • Shutdown your computer or reboot your computer
  • Log Keystrokes
  • Download Files
  • Open an FTP server on your machine


Discovered Trojan: June 6, 1999

Systems Affected:
  • Windows 2000, Windows 95, Windows 98
  • Windows Me, Windows NT, Windows XP


Known TCP ports for SubSeven::
  • 1243
  • 6711
  • 6712
  • 6713
  • 6776


Latest known version:
  • SubSeven Apocalypse
  • SubSeven 2.1.1 Gold
  • SubSeven 2.1.3 Bonus
  • SubSeven 2.1.4 DEFCO
  • Subseven 2.1.5 Legend



Screenshot: Sub7 Client Control Center

How to remove Subseven

This trojan tends to escape virus detection due to the fact that it morphs, or changes a little each time its sent to a new victim. By using a backdoor program such as: netbus or backorifice, an intruder can gain unauthorized access to the resources your machine has to offer.

Main Window. Allows the hacker to change different server settings. As you can see, one of the options is completely removing the server from the host machine.

Print - Allows a hacker to print anything out on your home printer. This is typically used by the pranksters.

Fun Manager - One of the many "fun" features SubSeven offers. This is the prankster-toy side of this malware.

Screen Capture. Allows a hacker to receive continuous screen shots of your screen. This mean that whatever you see, chat, e-mail, online shopping, the hacker sees as well. These live feeds can actually be saved so the hacker can play it back like a movie and go over any information he/she might have missed.



File Manager. Allows the hacker to copy, delete, rename, run any file on your computer.



Screenshot - Subseven Interface: This is the configuration utility edits the server settings.

Files on an infected machine:
  • server.exe
  • rundll1.exe
  • systray.dl
  • Task_bar.exe
  • FAVPNMCFEE.dll
  • MVOKH_32.dll
  • nodll.exe
  • watching.dll

Screenshot - Mac Edition: This one includes several remote command ( IP Notify, Numlock...)

How it loads, where it hides

It can be set to hide in just about any directory and can be loaded from the registry, system.ini, win.ini, and a few other less known places. Since the server editor that comes with Sub7 allows customization of startup, and the actual executable file, it is impossible to pinpoint the exact place Sub7 hides (since it's different with every file).

Subseven application tries to use ICQ, IRC and different e-mail accounts to notify the author that his victims are online.

All Sub7 components (files) should be deleted from an infected system for successful disinfection.

The worm drops a Trojan program to '\explorer.exe' that modifies different IIS settings (related to Code Red)t

NOTE: This information is supplied for educational purposes only. [January 2011]
Advertisement



What is Subseven Trojan?
  • Sub7; Subseven or Sub7Server is similar to Netbus or Backorifice. Once downloaded, this backdoor program tries to use ICQ, IRC and different e-mail accounts to notify the author that his victims are online.

    The Trojan horse program downloads because of an exploited bug in Internet Explorer or through an infected email attachment. To resolve this issue, install current antivirus software.

    Because the worm modified the registry so that you cannot run the .exe files. Once a PC is infected it allows the hacker access to all admin controls and files on the machine. Besides, Sub7 can also record every keystroke made on the computer.

    Find here the answers to the most commonly asked questions about trojan horse. Learn how to identify Internet threats and protect yourself online. This trojan horse program specifically targets Windows 95 and Windows 98.
Subseven Trojan - 2011 Edition
  1. SubSeven - Officical Site
  2. Backdoor.Subseven.22
  3. Win32-Sub7 trojan
  4. Port Scanner- Trojan List
  5. Backdoor-G
  6. Sub7.net
  7. SubSeven 2.1.5 removal
  8. SubSeven Trojan v 1.1 - FAQ
  9. BackDoor Sub7 - Introduction
  10. Sub7 Mac Edition
  11. Backdoor.SubSeven
  12. Virus Profile - BackDoor-Sub7
  13. Backdoor-CGT and Trojan horse attacks
Related to Site Reviews
  • Free Spyware Remover - Looking for anti-spyware that really works? Here's you'll find reviews of the best
  • Netbus Trojan Review - The biggest threat regarding malware is that most of them may be used to attack
  • Top Firewall Software - Learn about the latest technologies. Besides, we rank the best personal firewall
  • Top 10 Antivirus Software - To read our top-ranked antivirus programs review and see how they work by
  • Free Registry Repair - How to fix the Windows registry and system file errors? Read insightful software
  • Top 10 Antispam - Latest news about new anti-spam products, protection, evaluations, tips and tricks
2011 Internet Security - Sponsored Websites

Antivirus Software 2011 - Trend Micro antivirus with anti-spyware protects PCs from spyware, anti-phishing, virus, trojans and all other Internet threats. Best of all, it keeps intruders out and sensitive information in with a two-way firewall.

Firewall - ZoneAlarm Pro - The best way to secure your private information on your PC. Free services help you discover and recover from identity theft. ZoneAlarm Pro provides you with firewall with privacy protection. Scans for and removes thousands of spyware

AVG Antivirus with Anti-Spyware - AVG 9.0 brings a complete level of computer protection against the newest threats. It includes antivirus, firewall, with anti-spyware, and anti-spam. On top of that, the last major feature is a free support and

PC Tools Internet Security 2011 - is advanced technology designed especially for people, not just experts. It is automatically configured out of the box to give optimal protection with limited interaction. Best of all, it allows you to control

Norton 360 - Premier Edition - This new version detects and stops viruses, spyware, rootkits and other hidden threats automatically at their entry point or quarantines infected files when one is found on your computer. Protects up to 3 PCs per household.

ESET Smart Security 4 - Based on ESET NOD32 Antivirus, it protects you from viruses, worms, spyware, and all Internet threats; also blocks spam and includes personal firewall. Named "Consumer Digest Best Buy" in April 2008.

CensorNet Web Filter - CensorNet is a software solution for Web Content Security that protects against undesirable web sites and web based threats, delivering enhanced security and compliance.

Disk Doctors Windows Data Recovery - will help you bringing your lost data back. It can recover deleted files, lost partitions and accidentally formatted partitions. We recommend that you download the evaluation version first which will give you hand experience to try and test

Free Spyware Remover - Most computers that are connected to the internet today are infected by some sort of adware and spyware. You may have invested in the best security tools, but still it is advisable to use...

Web Blocking Internet Filter - The Safe Eyes Parental Control Software is the ideal online protection for you. It warns when kids post private information online. It allows you to control what applications each user can access on your PC. Besides, this top performer among internet

Security Scanner for Home Users - Infiltrator can audit each scanned computer for improper registry settings, suspicious open ports, vulnerable services, scripting exploits, weak password policies, and improper user configurations The program can be

GFI Software - Leading developer of network security, content security and messaging software. Its product range includes email content exploit checking and anti-virus software; security scanning and patch management tools.

2011 - PC Health Advisor - tackles all of your Windows PC’s performance issues. On top of that, this utility combines together all the tools you need at your fingertips. Offers free computer checkup and protects privacy by clearing out Internet history and cache