Event ID - 15382

Port No15382
Service NameSubZero
RFC Doc0
ProtocolTCP
DescriptionSubZero alpha is a early release with many incomplete features. When we tested the SubZero server it copied itself to the windows system directory. However it did not autoload with windows, which is probably because this is a alpha version. On December 21st, 2000 the author stated that he will no longer develop SubZero. He also said he would not released any source code
Reference LinkSubZero
AttackFeatures:

AIM, ICQ, IE, MSN and YAHOO spy
Change resolution
Change volume
Chat with server
Clear, get or set clipboard
Change start button icon
Change windows colors
Control mouse
Disable/enable keyboard
Download and run file
Exit, log off, power off, reboot or shutdown windows
Find files
File manager
FTP server
Get AIM passwords
Get cached passwords
Get information
Get RAS (dial up) passwords
Get screen shot
Hide/show/disable/remove clock
Hide/show/disable/remove start button
Hide/show/disable/remove systray
Hide/show/disable/remove task bar
Key logger
Print
Port redirect
Record sound
Send message
Send to URL
Swap mouse buttons
View/kill processes
Window manager

Fix:
Reboot the computer or close taskmann.dll.exe.
Delete the trojan file taskmann.dll.exe in the windows system directory

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.