Search:  In

 Haan - Description


 Browse by name

 
 | misc | a | b | c | d | e | f | g | h | i | j | k | l | m | n | o | p | q | r | s | t | u | v | w | x | y | z |

Description:
from the doc:
-= ev0luti0n HTTP keylogger =-
~ expl0it_shad0w ~
Introduction
I wanted to make a keylogger with a difference, I dont think one has been made like this yet, if it has let me know. This is a Keylogger that records all the key strokes to a file, and it allows you to view them, just by typing the victims IP address in the Internet Explorer ( or some other Internet browser ). NOTE: the keylogger sucks, so im working on a better one.
Instructions
Follow these instructions.
1. Rename "Server.exe" to what ever you want, make it convincing, not like "TROJAN.exe" or "KEYLOGGER.exe".
2> Send it to them and tell them its a new hacking tool, NOTE: Try binding it with a real one. If you know how. ( Once the victim opens it, it hides in memory and records all the key strokes on the computer, so you can view them with an Internet Browser like MSIE. )
3> Connect to there machine on port 80 with an Internet browser, as stated above. Type in there IP address into it and just hit Enter. For example if the victims IP address was 127.0.0.1 you type in http://127.0.0.1 or just 127.0.0.1.
4> have Phunn.
Trojan Removal
Follow these simple instruction to remove ALL traces of the trojan.
1> Goto inside the windowssystem directory and remove all these files.
smsg.html - Online HTML file
wincmd.exe - The Trojan Itself
Msvbrt60.dll - A needed DLL
evlog.dat - Stored keystokes
NOTE: If you can not delete wincmd.exe, or any of the other files, just boot into MS-DOS and delete them there. using the Del command.
2> Open up your Registry Editor and remove the following entry.
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunWincmd - its a string.
3> Thats it.


Alias:
Backdoor.Haan

Category:
Key Logger
Backdoor

Automatic Removal: Most effective removal tool is: Easy SpyRemover

Manual Removal:



Stop Runnin Processes:
Windows\system\wincmd.exe
Windows\temp\server\server\ev0.exe



Unregister DLLs:
Unknown


Clean Registry:
Unknown


Remove Files:
Windows\system\wincmd.exe
Windows\temp\server\server\ev0.exe

   


Latest Spyware Threats
    Comodo Trust Toolbar
    XP Antispyware 2009
    Antivirus 2010
    Freview
    RegistryGreat
    XPAntivirus
    Windows Antivirus 2008
    IE AntiVirus
    SpywareQuake 4
    Antivirus XP
    SecurePCCleaner
    Trojan.FakeAlert



Copyright © PcRepairCentral, 2005.