tequila bandita 1.2b3 v2
(Backdoor.Win32.Banito.t)
(Backdoor.Win32.Banito.o for Server)

by stm

Written in Delphi

Released in September 2004

more versions


Changes in 1.2 beta 3:
Fixed:
- -you can now use letters in modifying/creating reg values (oops)
- -Like 18 bugs in the registry manager
- -Disabled JPG and PNG options when your in the middle of a screen cap (crashed when changed before)
- -Send Keys hang
- -activex reboot hang
- -cancel open file for upload actually cancels
Removed:
- -custom dll loader
Replaced:
- -my TranslateVirtualKey function with GetKeyNameText api in the keylogger
- -melt method with a simpler one
Added:
- -default browser injection
- -service manager

stm


Server:
dropped file:
c:\WINDOWS\winhost32.exe
size: 17,920 bytes 

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\ActiveX Key "StubPath"
data: C:\WINDOWS\winhost32.exe



tested on Windows XP
January 03, 2006

MegaSecurity