Evade 1.1b
(Backdoor.Win32.VB.wa)

by FeraliX

Written in Visual Basic

Released in September 2004

more versions


Change Log/Info
I Made A Big Decision Last Minute And Decided To Switch This To Just Reverse Connection. I Ended Up Changing Up The Entire GUI And Options.
• I Turned This Into A Plugin Trojan, The Only Option Is A File Manager, Everything Else Was Removed.
• Current Plugins: Passwords. (A Whole Whopping One Plugin...)
• Combined The Client And Server Builder Into One.
• Dropped The Skin.
• Server Is 13kb Packed With UPX, 44kb Unpacked.
• I Definately Adding A Bunch More Plugin's Next Version, I Thought I Would Do One And Release For Testing.
   (Currently Working On Game Keys, More Passwords, Keylogger, And Remote Shell.)

Bugs/Errors
• File Manager Bug Where It Won't Upload Sometime's.
• There Might Be Some Problem's With My Ghetto Plugin System.
• I Hope I Fixed All The Other One's But I Probably Forgot -.-

FeraliX



Server:
dropped file:
c:\WINNT\system32\winhost.exe

size: 13.390 bytes (packed)

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WinHost Module"
data: C:\WINNT\system32\winhost.exe 

tested on Win2000

MegaSecurity