Services    Trojan info    Chat    Downloads      About Us      Contact  Us     Help Forum     Support Us    Search

Executor trojan
Executor trojan is a nasty trojan which  has a sole purpose of totally screwing over and wrecking the infected computer, it is an evil trojan and one that should be avoided at all costs

Description:-
Client - Controller.exe (313856)
Server - Exec.exe (231424)
Used ports - 80
Registry - Does not register

Functions
- Destroy Mouse Double Click
- Change All System Colors To Yellow
- Hang Up All Connections
- Disable CTRL+ALT+DEL Keys
- Set Cursor Position To 0,0
- Hide Windows taskbar
- Reboot Computer
- Enable Jumping Mouse
- Enable Mouse Double Click
- Enable CTRL+ALT+DEL Keys
- Show Windows taskbar
- Disable Jumping Mouse
- Copy EXECUTOR To C:\WINDOWS\ Directory
- Add EXECUTOR To Windows StartUp
- Show Message-'Hello'
- Show Message-'Hello bitch!!!!!!!!!!!!!!'
- Show Message-'Do u ready to fuck your system??????!!!'
- Show Message-'ShutUp bitch!!!!!!!!!!'
- Show Message-'Get ready to start!!!!!!'
- Show Message-'Thats All bitch!!!!!!!!!'
- Delete C:\Logo.sys
- Delete C:\Windows\Win.com
- Delete C:\IO.sys
- Delete C:\Windows\System.ini
- Delete C:\Windows\Win.ini
- Delete C:\Config.sys
- Delete C:\Autoexec.bat
- Enable Paiting On The Screen('DIE!!! DIE!!! DIE!!!')
- Disable Paiting On The Screen('DIE!!! DIE!!! DIE!!!')
- Enable Creating Of Many Forms With Caption

Firehotker backdoorz
I don't know a lot about this trojan but it sounds a lot like wincrash in what it can do  as far as remote access functions are concerned .
Here is a list of its remote access functions :-
- Active Process
- Chat with server
- Fatal Error
- Flip Screen
- Listen
- Modify Autoexec
- Open Hard Disk
- Steal passwords
- Capture Screen
- Delete Files
- Message Box
- Open/Close CD-ROM
- Play Wav Files
- Modify Date
- Send text
- Spawn Programs
Firehotker doesn't register itself in your registry so the best way to remove it would be to delete the server  which is named server.exe
You can also block port 5321 because that is the port that the server opens and this will stop your computer being attacked through this port .