System33r Socks5 (klorin) 1.1b
(Not detected by AVP on October 08, 2004)
(Constructor.Win32.SS.11.b for editor)

by System33r (k0nsl)

Released in October 2004

more versions


System33r Socks5 (klorin) v1.1b by System33r (k0nsl@msn.com)

System33r Socks5 is a socks5 server with a 'trojan'-like behaviour (extremely stable)


Main Features:
- SubSeven CGI Notification
- Installation Routine (Copies to SystemDirectory, and adds Registry entries)
- If Registry entries are deleted the Server adds them again
- DeleteSelf (melt)
- Identd (will be extracted from your username)
- Custom Registry Key (eg. Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run)
- It's horribly stable
- Small Size: 4,kb ( 7,kb unpacked)
- Included my slightly modified Sub7 CGI Logger
- Editor remembers your settings

System33r


Server:
dropped file:
c:\WINNT\system32\test.exe

size: 3.989 bytes (packed)
 
port: 113, 9035 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Script Host"
data: C:\WINNT\system32\test.exe 
	
tested on Win2000

MegaSecurity