Evade 1.13
(Backdoor.Win32.VB.wm)

by FeraliX

Written in Visual Basic

Released in January 2005

more versions


hange Log/Info
• Fixed Several File Manager Bugs.
• Finished The File Manager GUI.
• Fixed A Reverse Notification Bug.
• 15 Min SIN Timeout.
• A Bunch Of GUI Changes.
• Added Download File.
• Recoded File Transfer. (Based On Alchemists)
• Server Is 13kb Packed With UPX.

FeraliX



Server:
dropped file:
c:\WINDOWS\system32\winhost.exe
size: 13,371 bytes 

port: 9999 TCP

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Host"
data: C:\WINDOWS\system32\winhost.exe 



tested on Windows XP
March 15, 2005

MegaSecurity