Bandook 1.1
(Backdoor.Win32.Bandok.a for Client)
(Backdoor.Win32.Bandok.b for Server)

by Princeali

Server packed with FSG

Released in April 2005

more versions




Bandook v1.1 By Princeali
============================================================================================
Bandook is a  fwb+ Reverse connection 
Mass updater (Downloader) / Socks 4 Server
with a Tiny Size (3.4 kb) compressed.

Changes in v1.1
============================================================================================
-Firewall bypass Plus Tech
-Multi Threaded System
-Download/Update Abort Command
-Socks 4 Server engine
-Auto Download on Connect option
-Gets uptime
-Cam Detection
-Ping System
-Detect Clients reconnections and notify user
-Gets Local IP
-FIXED the Send system 
-Fixed Access Violation Warnings
-Added Remove Function
-Added Socket Info 

Features:
============================================================================================
-Fwbp+ using the Default Browser .
-Download and run any File from web on 1 Target .
-Mass Download/run any File from web on all targers.
-Turn your target to a Socks 4 Server .
-all commands are sent encrypted between Server/Client.

PING SYSTEM 
============
RPL (NUMBER) :  the ping reply u will know that ur vics are still connected
RCN          :  Your vic has just reconnected

Bandook in Lebanese means Child from mixed race
parents ,so since this Software is a mix between 
C++ / delphi its called  bandook .



============================================================================================
Thx : akcom ,archphase Caesar2k , drocon , Khe .
============================================================================================

Princeali


Server:
dropped file:
c:\WINDOWS\system32\ali.exe
size: 3,769 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "bandook"
data: ali.exe




tested on Windows XP
April 14, 2005
MegaSecurity