System33r Socks5 (klorin) 1.1b
(Not detected by AVP on October 08, 2004)
(Constructor.Win32.SS.11.b for editor)

by System33r (k0nsl)

Released in October 2004

more versions


System33r Socks5 (klorin) v1.1b by System33r ([email protected])

System33r Socks5 is a socks5 server with a 'trojan'-like behaviour (extremely stable)


Main Features:
- SubSeven CGI Notification
- Installation Routine (Copies to SystemDirectory, and adds Registry entries)
- If Registry entries are deleted the Server adds them again
- DeleteSelf (melt)
- Identd (will be extracted from your username)
- Custom Registry Key (eg. Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run)
- It's horribly stable
- Small Size: 4,kb ( 7,kb unpacked)
- Included my slightly modified Sub7 CGI Logger
- Editor remembers your settings

System33r


Server:
dropped file:
c:\WINNT\system32\test.exe

size: 3.989 bytes (packed)
 
port: 113, 9035 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Script Host"
data: C:\WINNT\system32\test.exe 
	
tested on Win2000

MegaSecurity