KaoTan 1.0
(TrojanDownloader.Win32.KaoTan)

by Faiseur

Written in ASM

Released in march 2004

Made in Switzerland

more versions



-------------------------------------------------------------------------------
                                How it Works
-------------------------------------------------------------------------------

KaoTan is a webdownloader made to suit users' needs. Here are its features :

- You can download up to 2 files

- 3 directories where the downloaded files can be saved :
a. Windows
b. Temp
c. System

- Injection modes :
a. No injection ( standard connection )
b. Browser injection
c. Explorer injection
d. Trillian/MSN injection

- You can set up a timer, thus delaying the execution :
a. Off
b. 30 seconds
c. 1 minute
d. 5 minutes

- The server can melt, once ran

- Critical data such as the URL to the file to download, or the names of the .exe, are encrypted


-------------------------------------------------------------------------------
                             Configuration
-------------------------------------------------------------------------------

The Edit Server has two sides. On the "server" side, enter the exact URL to the files you
want to download, and the name they'll be renamed to, once saved on the computer.
Tick the "URL 2 OFF" box, if you only want one file to be downloaded.

On the "Options" side, you can :


- Choose the type of injection you want :
a. No injection ( standard connection )
b. Browser injection
c. Explorer injection
d. Trillian/MSN injection

- Choose if the server should melt, once ran

- Set up a timer :
a. Off
b. 30 seconds
c. 1 minute
d. 5 minutes

- Choose the directory where the downloaded files will be saved :
a. Windows
b. Temp
c. System

- Give a look to the "About" ;)


Notice that the edit server saves your preferences.


Now, about the different injection modes, here are a few explanations,
so that you can choose the one that suits you best :

- If you choose the Browser injection, KaoTan will first check if a browser is currently running.
  If no browser is running, it will check for the default browser, run it, and inject itself in it.
  If, for any reason, no browser is currently running, KaoTan will then launch Internet Explorer,
  in hidden mode, and use it for injection. If, for any reason, Internet Explorer cannot be ran,
  KaoTan will then switch itself to Trillian/MSN injection mode...

- if the Trillian/MSN injection is chosen, KaoTan will first check if MSN is running.
  If it isn't, it will check for Trillian. If Trillian isn't running either, then KaoTan will
  launch MSN, in hidden mode, and use if for injection. If, for any reason, MSN cannot be ran,
  KaoTan will switch itself to browser injection mode.

By now, you should have understood that the choice of the injection mode is nothing but a choice of priority.
Those two modes ( Trillian-MSN, and Browser ) are quite secured.

Now, concerning the two remaining injection choices :
- The Explorer injection uses no "just in case" injection replacement, because it
  should always work ( unless Windows has been shutdown, of course ... )
- No comment about the "No Injection" mode ... :)


-------------------------------------------------------------------------------
                                About
-------------------------------------------------------------------------------


- KaoTan is not compatible with Win9x systems, but works perfectly with NT systems as WinNT, Win2K, WinXP, etc ... )

- Do not use this program in illegal ways. Just understand that you are responsible for
  any damage you cause on computers you do not own.

- Big thank you to the UndergroundKonnekt Team. English translation of the readme : Lucifer0000.

Faiseur


Server:
size: 9.216 bytes

MegaSecurity