System33r Socks5 (klorin) 1.0
(Not detected by AVP on October 15, 2004)
(Constructor.Win32.SS.11.b for editor)

by System33r (k0nsl)

Released in October 2004

more versions


System33r Socks5 (klorin) v1.0 by System33r (k0nsl@msn.com)

System33r Socks5 is a socks5 server with a 'trojan'-like behaviour (extremely stable)

Main Features:
- SubSeven CGI Notification
- Installation (Copies to SystemDirectory, and adds Registry entries)
- DeleteSelf (melt)
- Identd
- It's horribly stable

System33r


Server:
dropped file:
c:\WINDOWS\system32\test.exe
size: 4.113 bytes
 
port: 113 TCP

startup:
KEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Script Host"
data: C:\WINDOWS\System32\test.exe 

tested on Windows XP

MegaSecurity