Aphex's Remote Packet Sniffer 0.1.1
(Trojan.Win32.AphexSniffer.011)

by Aphex

Written in Delphi

Released in may 2002

more versions


Aphex's Remote Packet Sniffer 0.1.1

Capture IPs - Logs all traffic to and from these ip addresses
Capture Ports - Logs all traffic to and from these ports
Capture Strings - Loggs all traffic containing these strings (CASE SENSITIVE)

Server IP - Ip address of the PacketServer
Server Port - Port of the PacketServer
Server Pwd - Password of the PacketServer
Server Log - Logfile that the PacketServer will save traffic to

Transmit Settings - Send the PacketServer your new settings
Retrieve Settings - Get the current PacketServer settings

This is not by any means a complete server. It has one function and that is to log traffic. 
You will need to administer the PacketServer with another remote access server. 

You must install winpcap on the remote computer first. It installs invisibly thanks to stan!

You can have the sniffer log traffic to the logfile even when you are not running the client. 
Simply close the client without clicking "Stop Capture!".

There is currently not an editserver the defualt values are:

Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Explorer.exe
Startup File: %System%\Explorer.exe
Port: 8090
Password: aphex
Logfile: C:\packet.log

You can change the logfile but it will only remember it until the next restart.


Server:
C:\WINDOWS\SYSTEM\Explorer.exe 

size 462 KB

port: 8090 TCP

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run 

MegaSecurity