C.I.A Cruel Intentionz 1.23 Pb1 v2
(Backdoor.Win32.Ciadoor.123.b for Client)
(Backdoor.Win32.Ciadoor.102 for logger)
(Backdoor.Win32.Ciadoor.123.a for Server)

by Alchemist

Written in Visual Basic

Released in August 2004

more versions


CIA 1.23 PB 1 ( Public Beta 1 )

Added.......

Server Compiled to native code ( faster more stable however makes the server larger )
Removed Server Dependancy cjpg.dll ( Capture Plugin )
Server Compresses its own jpeg files
Capture Screen/Webcam/Windows with greyscale jpeg's 
Improved CGI/PHP logging system ( logs country , Webcam & Operating System - Check Loggers Directory )
Server is Semi-Polymorhic sometimes only 7% The same signature ( packed with upx )
Dos Shell ( capture the output of remote commands )
New Skin 
Turn on/off SIN Alerts
Detailed Connection Monitor
Grab Yahoo passwords in password recovery
New Icon Selector in Server Builder
Server Builder Combined into Client "Client Options"
Server Reports back Error's
Dont Send Notify's if Detects LAN ( 192.*.*.* )
Detect Server Connection ( Modem / Lan / Proxy )
Get System Uptime In Information
Set Max size of Offline Keylogger
Get More Paths In Information
Get Sound Card Driver in Info
Get Drivers Info
Get Installed Fonts
Edit Server is now resizable
Cd Keys Updates ( Thx 2 Death-Wish who did all the hard work )
Delete Files By Path ( File Manager )
Goto custom path ( File Manager )
Enumerate Registry keys
Brute Force Server Protection ( 10 Wrong passes = Banned IP)
Update Server Option ( Server name must differ from old server!! )
Remote Emailer with attachments Added in - Communication
Add multiple php/cgi/icq Notify ( Icq seems down )
You can changed the string that gets sent in CGI/PHP Notfiy
Added a webdloader ( download on install or control from client )
Added Binder In Editor ( Any File Type & Plugins Can be binded to the server )


New Recovery Option - Misc Info -

          Get Recently opened media files
          Get recently searched files
          Get recently Opened files
          Get Recnetly Run Files

New Administration Option - Misc Control - 
          
          Disable Command Prompt
          Enable Command Prompt
          Disable System Restore
          Enable System Restore
          Disable Task Manager
          Enable Task Manager
          Disable Registry Editor
          Enable Registry Editor

New Misc Editor Options -

	  Disable System Restore
	  Disable Command Prompt

New section in Editor - Stealth Options -

	  Hide Processes from Task Manager ( Tested & Working on XP Pro May Flicker due 2 auto refresh )
	  Hide Files From Windows Explorer ( Tested & Working on XP Pro English )
	  Hide Values From RegEdit ( Seems 2 Work on All NT Systems )
	  Hide Names From Msconfig.exe ( Tested & Working on XP Pro English )

WARNING!!!!: These options are extremely beta stage the explorer hide has been known to use 100% CPU when explorer windows are open i recommend you test these options and make your own mind up if you should use them or not!!!

Server Can Use Global variables - ( Can be used any where any time )

%AC% = Area Code
%AD% = Application Data Path
%CK% = Cookies Path
%CO% = Country
%CN% = Computer Name
%CR% = Currency
%CT% = Connection Type
%DP% = Desktop Path
%DT% = Date
%FT% = Fonts Path
%FV% = Favorites Path
%HP% = History Path
%IN% = Install EXE Name
%IV% = IE Version
%IP% = Ip Address
%LG% = Language
%MD% = My Docs Path
%MF% = Free Memory
%MT% = Total Memory
%NH% = Nethood Path
%OS% = Operating System
%PG% = Programs Path
%PH% = Printhood Path
%PN% = Printer Name
%RD% = Recent Docs Path
%PS% = Processor Speed
%RS% = Resolution
%RV% = Server Registry Value
%SD% = System Directory
%SM% = Start Menu Path
%ST% = Send To Path
%SU% = Start Up Path
%TI% = Temp Internet Files Path
%TM% = Time
%TP% = Templates Path
%UN% = User Name
%UT% = Sytem Uptime
%WC% = Webcam Drivers
%WD% = Windows Directory
%SV% = Server Version
| = NewLine

Fixed.......

Transfer problems resolved
Webcam Issues Resolved 
Full Screen Chat fixed
Process Manager fixed
Service Manager Auto Refreshes
Power Options Changed & working on XP
Upload/Download Files of any size will no longer crash if over 60 mb
Email Notify Fixed ( works with hotmail )
Ftp Server removed untill 1.3 ( to buggy )
Message Box Body & Title Mix up Fixed
Removed Yahoo plugin ( gets yahoo passwords now any way just using up space )

Alchemist


Server:
dropped files:
c:\WINDOWS\WinIogon.exe 
size: 122.637 bytes
 
c:\WINDOWS\SYSTEM\ckl009.dat 
size: 795 bytes

port: 6333 TCP

startup;
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Windows Logon Application"
data: C:\WINDOWS\WinIogon.exe

c:\windows\system.ini, [boot] "shell" 

MegaSecurity