SubRoot 1.0
(Backdoor.Win32.Subroot.10)

by cloak

Written in Delphi

Released in February 2003

more versions


  SUBROOT v1.0  -  ( RTA backdor # )
  by cloak
  subroot @ subdimension.com

  This program is provided 'as is'. The author claims no responsibility
  for your actions and the actions against you resulting from the use 
  of this program. This program is intended for educational purposes
  only and not for illegal actions for which you will bear the full
  consequences.


  About:
  ~~~~~     
  SubRoot is a Remote Telnet Administration Tool for Windows. It uses 
  the TCP/IP protocol and listens for connections on port 1700. SubRoot
  was written and tested in the Republic of South Africa.


  Username and Password:
  ~~~~~~~~~~~~~~~~~~~~~
  Subroot uses 'Username and Password' authentification to prevent others from 
  connecting to the server. Default settings are as follows:

  USERNAME: root
  PASSWORD: admin

  NOTE: Only ONE connection will be allowed to the server at a time.
  ~~~~  Only ONE server may run on the remote computer at a time. If a 
        second is run, the following error will be displayed:

        Rundll
        Run-time error '10048'
        Address in use.

  
  System requirements:
  ~~~~~~~~~~~~~~~~~~~~
  [SERVER]
   Micro$oft Windows 95/98/2000
 
  [CLIENT]
   Any Operating System with a Telnet client installed. (Buffer size = 25)
 

  Commands:
  ~~~~~~~~

* dir <dir\>
  - Gives directory listings. Make sure to put a \ at the end to show that 
    it is a directory and not a file. EG:  dir c:\windows\ 

* kill <filepath> or <dir\>
  - Deletes a specified file or directory. Again make sure to put a \ at the 
    end to show if it is a directory or file extension if it is a file. SubRoot
    will only delete a directory if it is empty.
    EG:  kill c:\windows\notepad.exe
         kill c:\porn\

* run <filepath>
  - Runs a specified file on server. EG:  run c:\windows\explorer.exe

* read <filepath>
  - Reads a specified file from server. If the file you are reading is larger 
    and cannot be displayed in your telnet client. Then use logging on your telnet 
    client and log to a file, then read it from that file. 
    EG:  read c:\windows\faq.txt

* listfree <drive\>
  - Lists the amount of free space in a specified drive. Make sure you put
    a \ after the drive. EG:  listfree c:\

* shell <web address>
  - Opens a specified URL or any website on the remote computer.
    EG:  shell http://www.childporn.org/
         shell ftp://warez.illegal.com/
         shell c:\nudeboyz\

* opencd
  - Opens CD-ROM on server.

* closecd
  - Closes CD-ROM on server

* swapmouse
  - Swaps server's left & right mouse buttons around.

* swapmouseback
  - Swaps server's left & right mouse buttons back to normal.

* beep
  - Makes the PC speaker beep.

* beepoff
  - Stops the PC speaker from beeping.

* hidestartbutton
  - Hides the start button.

* showstartbutton
  - Shows the start button.

* hidetaskbar
  - Hides the taskbar.

* showtaskbar
  - Shows the taskbar.

* startcolour
  - Cycles through windows colours.

* stopcolour
  - Stops cycling through windows colours.

* disablecad
  - Disables Ctrl-Alt-Delete.

* enablecad
  - Enables Ctrl-Alt-Delete.

* info
  - Lists the following information about the server:

     Resolution : (Server's resolution)
     Username   : (Windows Username)
     Soundcard  : (If soundcard is installed or not?)
     Total RAM  : (Total RAM)
     Free RAM   : (Free RAM)
     Time       : (Server Time)
     Date       : (Server Date)

* sendmsg
  - Sends a popup message to the server.

* dboot
  - DONT use this command unless you really have to! Sets computer so that
    the user has to re-install Windows next time he restarts.

* reboot
  - Reboots server.

* shutdown
  - Shutsdown server.
   
* freboot
  - Force reboots server.

* close
  - Closes server.

* disconnect
  - Disconnects from server.

* cls
  - Clears telnet buffer.

* about
  - Lists SubRoot information.

* help
  - Displays commands.


  Contact information:
  ~~~~~~~~~~~~~~~~~~~
  ----------------------------------

  subroot @ subdimension.com

  -=- PROGRAMMER -=-

  name   : Cloak 
  email  : cloak @ phreaker.net
  
  ----------------------------------

  name   : Glitch
  email  : (undisclosed)
 
   ----------------------------------


Server:
c:\windows\system\ssetup17.exe

size: 94.208 bytes

port: 1700 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices "Ssetup17" 

MegaSecurity