Services    Trojan info    Chat    Downloads      About Us      Contact  Us     Help Forum     Support Us    Search

Fakeftp
Fake ftp  is a basic trojan , it installs an ftp server on the victims computer , if you don't know what a ftp server is , it's a file transfer server allowing the hacker access to the victims files where  the hacker can doiwnload , upload delete etc .
Another interesting thing about this trojan is it isnt the uasal executable type of file ( .exe ) but instead it comes in  a made up file format called .tww  . The trojan will make windows treat this as a executable and infect the victim . This trojan will run on windows 95/98 and also windows NT

How to remove this trojan  :
Open RegEdit. Click on Start, and choose Run. In the box type regedit, then click Run.
You can click on the + boxes to open a folder. You will want to open folders to follow this path:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
When you click on Run, the right hand panel will change.
You should see an item titled Rundll32 = rundll3.tww /h
Right click on the Rundll32 label and choose Delete.
Repeat this with the following path:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
You should see an item titled Rundll32 = rundll3.tww /h
Right click on the Rundll32 label and choose Delete.
Close regedit to save these changes.
Next, open windows explorer, and open your C:\windows\ folder.
You will want to find and delete the following three files:
rundll3.bat - 9x.reg - nt.reg
Then you will want to restart your computer, this will remove the trojan from memory.
When the system starts up, use the windows Find command and search for rundll3.tww
Delete Any instance of this that shows. There should be atleast one copy in c:\windows\ and one in C:\windows\temp\

Girlfriend
Girlfriend is a fairly old trojan now , but it was one of the first of its type to be made specifically for stealing passwords . This Russian made trojan acts as a remote keylogger logging all keys typed in password fields etc , it can also do some other basic things similar to netbus but is best known for its password stealing and abilities

Here is a list of girlfriends functions:
- text, that "infected" user enters to any window containing password field;
- passwords, which "infected" user enters to password fields.
- send "system" messages to remote PC;
- play sounds;
- show bitmaps (.bmp pictures);
- send "victim" to any URL;
- change server's port;
- hide  Client with BOSSKEY=F12;
-scan subnet for infected servers;
- ping server;
- save windows list;
- takes passwords from Web sites which infected user inputs

The easy way to tell if your infected is to use regedit and look in
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
with the entry
Windll.exe =    "C:\windows\windll.exe"
The server will also save its data in the regedit item
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\General
You can also delete the items titled Girlfriend in here as well.
Simply remove the first registry item, and delete the program it points to.