tequila bandita 1.2b2
(Backdoor.Win32.Banito.af for Client)
(Backdoor.Win32.Banito.ae for Server)

by stm

Written in Delphi

Released in

more versions





Server:
dropped file:
c:\WINDOWS\winhost32.exe
size: 24,576 bytes 

startup:	
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\ActiveX Key "StubPath"
data: C:\WINDOWS\winhost32.exe	


	
tested on Windows XP
December 15, 2005

MegaSecurity