tequila bandita 1.2b2
(Backdoor.Win32.Banito.l)
(Backdoor.Win32.Banito.plugin.a)
(Backdoor.Win32.Banito.plugin.b)
(Backdoor.Win32.Banito.plugin.c)
(Backdoor.Win32.Banito.plugin.d)

by stm

Written in Delphi

Released in August 2004

more versions


Changes in 1.2 beta 2:
Fixed:
- -Save Keylog to Text
- -Few visual bugs
- -servers wouldn't reconnect after "hard" disconnects
- -other stuff
Removed:
- -Socket field in connection list (actually, i just changed the width to 0)
Replaced:
- -Kill/Close Process/window Sends ack. instead of refreshing list
- -switched my origional popup notify with a component
- -remote execution (FWB++) instead of dll injection
Added:
- -Customize ActiveX Key
- -Shows ActiveX Key Used in Computer Info
- -Remote Shell is now 9x compatible

stm


Server:
dropped file:
c:\WINNT\winhost32.exe

size: 18.432 bytes (UPX compressed)
 
startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\ActiveX Key "StubPath"
data: C:\WINNT\winhost32.exe
	
tested on win2000	

MegaSecurity