Sub7 is a trojan (or as its users like to call it "Remote Administration Tool") in the line of back orifice and netbus. It has the power of back orifice, the user-friendliness of netbus and the features of both.The program allows one to gain remote access to another computer if the other computer has a server running. The catch is that the victims do not know that the Sub7 servers running on their box. Once connected users can access files and change settings on the other computer as if it was their own. Their are also some fun extras such as the ability to log all keys typed, get screen captures, kill apps, etc.

How to remove:

1. Run 'msconfig'(on windows 9*/ME).
2. Find the trojan in the start-up programs list.
3. Disable it and restart.
4. Delete the file.

on NT or 2k you'll probably have to find the start-up key in the registry(run 'regedit') in:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Now delete the key, restart and delete the file.

If you're on NT or 2k you might also want to check system.ini or win.ini for a 'RUN=' line. msconfig does this for you in 9x/ME.
Y'know, if you log in, you can write something here, or contact authors directly on the site. Create a New User if you don't already have an account.