NETObserve 2.9
(RAT, not detected by AVP)

by ExploreAnywhere Software

Written in Delphi

Released in august 2002


Internet Conversation Logging - Log both sides of all chat conversations for 
AOL/ICQ/MSN/AIM/Yahoo Instant Messengers, and view them in real time. 

Window Activity Logging - Capture information concerning all windows that were viewed
and interacted with. 

Application Activity Logging - Track every application executable that was executed and interacted with. 

Clipboard Activity Logging  - Capture and store all text and image items that were
copied to the clipboard while the user was using the PC. 

Printed Documents Logging - Log specific information on all documents that were sent to the printer spool. 

Keystroke Monitoring - Track all keystrokes pressed and which windows they were pressed in.
Keystrokes can also be passed through a formatter for easy viewing/exporting. 

Websites Activity Logging  - Log all website titles and addresses that were visited on the PC.
Supported browsers include Internet Explorer, Netscape, and Opera. 

Screen Shot Capturing  - Automatically capture screen shots of the desktop at set intervals 
- perfect for visually seeing what is going on. 

Webcam Picture Capturing  - Automatically capture pictures from the web cam connected to the PC
 - perfect for seeing what is going on around the PC and not just what is going on inside the PC. 

 
Remote Administration Features 

File Sharing  - Browse directories/files in real time, as well as transfer files,
rename files, and delete files. 

Startup Moderating  - Remotely configure Windows startup applications by editing existing
startup application data, or by deleting applications from starting up on the machine running NETObserve. 

Image Cache Browsing  - Browse the remote machines Internet Explorer image cache.
Statistics for each image is included in the cache report - such as last view, total views, and more. 

Favorite Places  - Browse, launch, edit, delete, and manage Internet Explorer bookmarks 
on the remote machine. 

Internet Connection/Port Viewing  -View all open internet connections and open ports
on the machine running NETObserve. An integrated Whois Lookup is also included for instantly
retrieving information on any remote host. Perfect for spotting Trojans [malicious viruses],
or any possible open areas on your network that could lead to a dangerous situation. 

Process Management  - Remotely view open windows and processes on the machine running NETObserve. 
You can freely terminate or close a window with a single click. 

System Control  - Quickly shutdown/reboot/logoff the remote machine, as well as put the
machine into Lockdown Mode. Lockdown Mode will bar the PC of any usage, and the only 
way to regain control of it is if you [the administrator] unlocks it. 


Window Management  - Remotely deactive and kill windows (in real time) that you do not wish to be running.


 
Stealth Mode  - Run NETObserve in total stealth - the user will not know that it is running! 






Server:
C:\PROGRAM FILES\EXPLOREANYWHERE\NETOBSERVE\NETOBSERVE.EXE 

size: 1269 KB

port: 80 TCP

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "1Sys32Cfg" 

MegaSecurity