Evilotus 1.3.2
(Backdoor.Win32.Agent.alt)
(Trojan.Win32.Agent.bfw for Server)
(Trojan.Win32.Agent.fko for Evilotus.dll)

by ?


Released in February 2007

Made in China

more versions


Evilotus v1.3.2

-----------------------------------------
Evilotus is a reverse connection, remote administration tool
that allows you to remotely control computers.

-----------------------------------------
1.The main application is based on the completeion port I/O model.

2.The installation will recover SSDT.(Warning:Maybe crash your system!!)

3.Features:
File manager,Remote shell,Process list,Window list,Regedit,
Service/Driver list,Screen capture,Cam capture,Online keylogger,
Clipbord viewer,User list,Downloader and so on.

-----------------------------------------
Changelog:

v1.3.2
-Add an option to select if you don't want to recover SSDT
-The server is packed with UPX v2.03.If you want to modify the server,unpack it with "UPX -D"




Server:
dropped file:
c:\WINDOWS\system32\Evilotus.dll
size: 28,160 bytes 

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_EVILOTUS\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Evilotus
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_EVILOTUS\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Evilotus



tested on Windows XP
March 03, 2007, 2007

MegaSecurity