Toquito Bandito 1.1
(Backdoor.Win32.Banito.b)

by stm

Written in Delphi

Released in March 2004

more versions


Features:

--FWB (inject to explorer.exe), Melt, ActiveX startup, and install to win dir options.
--Aim Spy
--webcam and screen capture
--Offline Keylogger
--File, Task (with send keys), Process, and Registry managers
--computer info
--webdownload
--Broadcast commands: uninstall, close, reset, webdownload, upload.


Fixes in 1.1:
--added: PHP notify (ParaSite support!)
--added: a few new stuff in comp info
--added: uninstall melts the server and dlls
--lil Client visual tweeks
--client crash problems fixed (i hope)
--server injection problems fixed
--activex problems fixed
--other bugs i forgot about...

stm


Server:
dropped file:
c:\WINDOWS\winhost32.exe 

size: 20.480 bytes 

size: 19.456 bytes 

startup:
HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{tv9381D8F2-0288-11D0-9501-00AA00B911A5} "StubPath" 

MegaSecurity