tequila bandita 1.2b3
(Backdoor.Win32.Banito.q for Client)
(Backdoor.Win32.Banito.o for Server)

by stm

Written in Delphi

Released in September 2004

more versions


Changes in 1.2 beta 3:
Fixed:
- -you can now use letters in modifying/creating reg values (oops)
- -Like 18 bugs in the registry manager
- -Disabled JPG and PNG options when your in the middle of a screen cap (crashed when changed before)
- -Send Keys hang
- -activex reboot hang
- -cancel open file for upload actually cancels
Removed:
- -custom dll loader
Replaced:
- -my TranslateVirtualKey function with GetKeyNameText api in the keylogger
- -melt method with a simpler one
Added:
- -default browser injection
- -service manager

stm


Server:
dropped file:
c:\WINNT\winhost32.exe

size: 17.920 bytes 
 
startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\ActiveX Key "StubPath"
data: C:\WINNT\winhost32.exe
	
tested on win2000	

MegaSecurity