Poison Ivy 2.1.0
(not-a-virus:RemoteAdmin.Win32.Poisonivy.a)
(Trojan.Win32.Small.js for Server)

by shapeless

Written in Delphi

Released in August 2006

more versions

 


Description
PI2.1.0 is a reverse connection, fwb+ remote administration tool, written in masm (server) and Delphi (client).
Due to its design nature, a server update is hardly needed, regardless of how many new features are added.
Also note that PI2.1.0 does not use any plugins/dlls or any other files besides the server, and does not drop any other
files on the target system (except for the key logger log file).
The server is only 7 KiB unpacked, is independent of any runtimes, and runs an all NT based windows systems (NT,
2000, XP, 2003, Vista), 32bit or 64bit.
It also features firewall bypassing techniques.
The main features are:
� ARC4 encrypted communications
� transparent compression of transfers and communications
� managers:
� files (with search, also in file contents)
� registry (with search)
� services
� processes
� ports
� passwords manager (protected storage, Firefox, and MSN <= 7.5)
� key logger
� socks4 server
� socks5 server
� port redirect
� traffic sniffer
� remote screen shot
� remote web cam view
� remote cmd shell
� ability to share a server with 3 privilege levels
 
shapeless


Server:
size: 7,168 bytes

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{112B7F82-1892-E4D0-0602-070704020806} "StubPath"

tested on Windows XP
August 26, 2006

MegaSecurity