Remote Keylogger & Desktop Spy
(TrojanSpy.Win32.Locha.a)

by Exhumed

Written in Visual Basic

Released in March 2002

more versions


Keylogger

Very simple to use:

* Keylogger
must connect to server

* Screen capture
Just run the program in the server side, then you can access the computer remotely using  your web browser (Internet explorer) and the Ip Address (even if the client is not connected).

  eg:
http://127.0.0.1/


to refresh the image:
http://127.0.0.1/desktop

note: 127.0.0.1 is your local Ip  address (to test locally) you have to get the remote IP address where the server is running.

Exhumed


Server:
dropped files:
c:\WINNT\system32\desktop.jpg size: 63.815 bytes 
c:\WINNT\system32\jpg.dll     size: 95.744 bytes 
c:\WINNT\system32\log32.exe   size: 65.536 bytes 

port: 123, 80 TCP

startup:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Microsoft"
data: log32.exe 

MegaSecurity