# SubSeven/Backdoor trojan?

**URL:** <https://boards.straightdope.com/t/subseven-backdoor-trojan/98673>\
**Category:** Factual Questions\
**Created:** [March 17, 2002, 1:08am UTC](https://boards.straightdope.com/t/subseven-backdoor-trojan/98673 "2002-03-17T01:08:20Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Caesar\_s\_Ghost](https://avatars.discourse-cdn.com/v4/letter/c/73ab20/32.png) [@Caesar\_s\_Ghost](https://boards.straightdope.com/u/Caesar_s_Ghost)\
**Post date:** [March 17, 2002, 1:08am UTC](https://boards.straightdope.com/t/subseven-backdoor-trojan/98673/1 "2002-03-17T01:08:20Z")

</div>

The firewall I have installed, Norton Personal Firewall, keeps giving me security alerts, blocking the same trojan all the time: the SubSeven or Backdoor trojan. What does this trojan hide in? I haven’t downloaded anything in a while.

---

<div class="post-metadata">

**Author:** ![DMC](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dmc/32/18049_2.png) [@DMC](https://boards.straightdope.com/u/DMC)\
**Post date:** [March 17, 2002, 1:17am UTC](https://boards.straightdope.com/t/subseven-backdoor-trojan/98673/2 "2002-03-17T01:17:54Z")

</div>

You can find info on the trojan as well as which software can eliminate it [here](http://www.hackfix.org/subseven/index.shtml) .

---

<div class="post-metadata">

**Author:** ![Caesar\_s\_Ghost](https://avatars.discourse-cdn.com/v4/letter/c/73ab20/32.png) [@Caesar\_s\_Ghost](https://boards.straightdope.com/u/Caesar_s_Ghost)\
**Post date:** [March 17, 2002, 1:18am UTC](https://boards.straightdope.com/t/subseven-backdoor-trojan/98673/3 "2002-03-17T01:18:54Z")

</div>

Thanks, **DMC**. I’ll check it out.

---

<div class="post-metadata">

**Author:** ![glilly](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@glilly](https://boards.straightdope.com/u/glilly)\
**Post date:** [March 17, 2002, 4:27am UTC](https://boards.straightdope.com/t/subseven-backdoor-trojan/98673/4 "2002-03-17T04:27:41Z")

</div>

I’m using Norton Firewall and Norton anti-virus (both 2002 versions), and I get the BackDoor/SubSeven alert all the time. However, the anti-virus doesn’t pick it up.

I can’t figure out if

1. I have this trojan and NAV can’t see it  
or
2. Norton Firewall is misinterpreting something as a trojan  
or
3. Norton Firewall is giving me fake alert after fake alert so I don’t feel I’ve wasted my money.

Any ideas?

---

<div class="post-metadata">

**Author:** ![Caesar\_s\_Ghost](https://avatars.discourse-cdn.com/v4/letter/c/73ab20/32.png) [@Caesar\_s\_Ghost](https://boards.straightdope.com/u/Caesar_s_Ghost)\
**Post date:** [March 17, 2002, 4:56am UTC](https://boards.straightdope.com/t/subseven-backdoor-trojan/98673/5 "2002-03-17T04:56:31Z")

</div>

Hm, maybe it’s a bug in the system then. Pretty weird bug though.

---

<div class="post-metadata">

**Author:** ![DMC](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dmc/32/18049_2.png) [@DMC](https://boards.straightdope.com/u/DMC)\
**Post date:** [March 17, 2002, 5:33am UTC](https://boards.straightdope.com/t/subseven-backdoor-trojan/98673/6 "2002-03-17T05:33:54Z")

</div>

glilly,

For Norton AV, use [these](http://www.symantec.com/avcenter/venc/data/backdoor.subseven.html) instructions (this assumes you have the Backdoor.SubSeven trojan and not another version of SubSeven.

---

<div class="post-metadata">

**Author:** ![cls](https://avatars.discourse-cdn.com/v4/letter/c/e68b1a/32.png) [@cls](https://boards.straightdope.com/u/cls)\
**Post date:** [March 17, 2002, 5:45am UTC](https://boards.straightdope.com/t/subseven-backdoor-trojan/98673/7 "2002-03-17T05:45:55Z")

</div>

If it reports it’s incoming, it means that some other computer is scanning for computers infected with SubSeven. It’s doesn’t necessarily mean you’re infected. They scan thousands of addresses and aren’t targeting you specifically nor trying to infect you with Subseven.
