Toquito Bandito 1.0
(Backdoor.Win32.Banito.10)

by stm

Written in Delphi

Released in March 2004

more versions


Features:

--FWB (inject to explorer.exe), Melt, ActiveX startup, and install to win dir options.
--Aim Spy
--webcam and screen capture
--Offline Keylogger
--File, Task (with send keys), Process, and Registry managers
--computer info
--webdownload
--Broadcast commands: uninstall, close, reset, webdownload, upload.

stm


Server:
dropped file:
c:\WINDOWS\dllhost128.exe 

size: 19.456 bytes 

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{tv9381D8F2-0288-11D0-9501-00AA00B911A5} "StubPath" 

MegaSecurity