PDA

View Full Version : Sagem S6 calculator (loger) its a TROIAN!!


cris
06-01-2001, 13:05
Sagem S6 calculator (loger) its a backdoor!!
Everybody who started the s6_calc.exe with the
backdoor/trojan: it will install a BACKDOOR_GQ server
into the C:\ directory. It's relatively easy to remove:
use regedit to remove the entry "sucareg.exe" or something
similar from the registry path

HKEY_LOCAL_MACHINE/Software/Microsoft/Windows/CurrentVersion/Run

Then delete the files sucareg.exe and TMP32$1.exe from c:\ )

Best regards,
Cris

Invader
06-13-2001, 12:14
Use something like Jammer for registry monitoring.
I have S6_Calc with backdoor.Y3K , But using Hex-Editor I repair this soft (File length 23K , not 323k!)