Fate Servers SE
(Backdoor.Backdoor.VB.eq)
(TrojanDropper.Win32.Decept.11 for e-m.com & fate.pif)

by ?

Written in Delphi

Released in january 2003


picture shown

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
!!    =============================================================================       !!
!!    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~       !!
!!                      [ Fate Servers, SPECIAL EDITION ]                                 !! 
!!    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~       !! 
!!    =============================================================================       !!
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

-----------|  
FILE:[e-m] | 
           |  
           ------------------------------------------------------------------------------>

 - Ok here is the first file, it is a .com file , once sent to the victim and opened it will 
   open a picture and execute the file in the background, then after execution the picture 
   will be present instead of the .com, so the guy will see "example.jpg" instead of e-m.com.
   Then all u have to do is scan and ur in :D ! Have Fun 

||-------------------------------------------------------------------------------------||


-----------|  
FILE:[Fate]| 
           |  
           ------------------------------------------------------------------------------>

 - Ok this is exaclt like e-m.com but this file has a .pif extention :D ! 
         

||-------------------------------------------------------------------------------------||

----------------|  
FILE:[mypic.scr]| 
                |
                ------------------------------------------------------------------------>

 - Ok this is a screen saver extention , and has a .jpg icon ! once opened it will launch    
   fates server and Boom you are in :D ! 
         
||-------------------------------------------------------------------------------------||

----------------|  
FILE:[mypic.zip]| 
                |
                ------------------------------------------------------------------------>

 - Ok this is my pride and joy, this is a real zip file , once unzipped and it will launch 
   Fate's server automatically (he has to be using winzip wizard! not classic) ! the victim 
   just needs to keep on pressing next and boom once he sees the properties of the screen savers
   pop up like he wants to change his screen saver he is infected ! :D enjoy guyz !
 
         



Files dropped by mypic.scr (281.350 bytes):
c:\WINDOWS\SYSTEM\aamd532.dll 
c:\WINDOWS\SYSTEM\Bmp2Jpeg.dll 
c:\WINDOWS\SYSTEM\smss.exe (Backdoor.Backdoor.VB.eq)

Files dropped by e-m.com (320.511 bytes):
c:\fate.JPG 
c:\Rename Me.exe (Backdoor.VB.eq)
c:\WINDOWS\SYSTEM\aamd532.dll 
c:\WINDOWS\SYSTEM\Bmp2Jpeg.dll 
c:\WINDOWS\SYSTEM\smss.exe (Backdoor.VB.eq)

MegaSecurity