Pastilatu' Posted August 8, 2006 Report Posted August 8, 2006 CIA Trojan 1.3 Screenshot:====================================================================New In This Version:====================================================================Quote:2 Methods of Fwb ( Firewall Bypass )- Spyware Method ( Uses a common method performed by various spyware applications to try and bypass software firewalls )- DLL Injection ( Injects server as a DLL in to a trusted process to try and bypass software firewalls )- Choose Fwb Into IE or Explorer- Choose Injected DLL namePlugin Engine- Easily create & design custom plugins in VB that can be used in the server- Full details & Examples included in package!Smaller Server ( As Small as 52 kb compressed & 171 kb uncompressed , size varies depending on settings )Server is now packed using MewCjpg.dll plugin is used now for captures (cuts servers size & faster compression)Informaton Is Scripted From Client Side ( Check Scripts folder - this saves server size by 10 - 20 kb and meens you can customize scripts to own needs )Unlimited amounts of scripts can be added ( CDkeys & Basically anything can be fetched from the registry )Added Siren Sound In NT BeeperAdded About 20+ More Global VariablesAdded Reverse Connection only server (better for bypassing FW's)Screen Clicks in Full Screen ModeAdded over 250 iconsCustom icons easily added to list in the "icons" folderUnblock Some Popular Firewalls ( XP Firewall & Sygate Ect ( Beta ) )Added FBI Chat Plugin thanks 2 Edjorges idea ( Includes Source )Added Msn Details Plugins Editor Plugin ( Includes Source )Added Example Fonts Plugins Editor Plugin ( Includes Source )Added Example Message Plugins Editor Plugin ( Includes Source )Added Auto-Start with server for plugins (example included)Added Auto-Start Plugins Editor PluginAdded Flowbys Text 2 Speech PluginUpgraded Binder -- ListView Upgraded From ListBox- Show File Path & Name- Show File Sizes- Choose File Destination- System Directory- Windows Directory- Temp Directory- Root Drive- Choose Execution Type- Run Hidden- Run Normal- Run Minimized- Run Maximized- No Execution- Plugin & DLL Options- Register Plugins/DLLs/OCXs- Choose Plugin To Autostart With Server====================================================================Changes/Bug Fixes====================================================================Server is build in VB6 especially for NT based operating systems ( No longer supports old windows 9x systems)Server much is smaller & uses less memoryFixed CPU usage issue with Explorer Hide FilesTaskmanger should no longer flicker in hiding processSystem Colors Bugs FixedFixed Multi Client Download BugChanged Server Builder LayoutChanged The Way Server Determinds if Plugin Is Installed ( hopefully better )Changed The SIN Code Slightly Should Work Better Now ( Fixed timing bug )SIN will now correctly delete any offline serversMouse Clicks More AccurateUpdated Matix Chat SlightlyUpdated & Fixed Socks4 ServerRemoved Dependency From Client ( MSINET.OCX & Smaller Client)Fixed SMTP Finder BugFixed Multiple File Binding BugMany More Tweaks & Fixes...AlchemistServer:dropped files:c:WINDOWSsystem32ckl009.dat size: 224 bytesc:WINDOWSsystem32DlQ936o14m.ini size: 54.847 bytesc:WINDOWSsystem32scvhost.exe size: 54.847 bytesc:WINDOWSsystem32wsock32.sys size: 163.328 bytesport: 6333, 6334, 6335 TCPadded to registry:HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurr entVersionRun "Generic Host Process"data: C:WINDOWSSystem32scvhost.exeHKEY_CURRENT_USERSoftwareVB and VBA Program SettingssetsetHKEY_CLASSES_ROOTCLSID{E14DCE67-8FB7-4721-8149-179BAA4D792C}InprocServer32HKEY_CLASSES_ROOTCLSID{E14DCE67-8FB7-4721-8149-179BAA4D792C}ProgIDHKEY_CLASSES_ROOTCLSID{E14DCE67-8FB7-4721-8149-179BAA4D792C}TypeLibHKEY_CLASSES_ROOTCLSID{E14DCE67-8FB7-4721-8149-179BAA4D792C}VERSIONHKEY_CLASSES_ROOTInterface{0958C4C9-77B0-4AA8-9364-7886BFCA7E39}ProxyStubClsidHKEY_CLASSES_ROOTInterface{0958C4C9-77B0-4AA8-9364-7886BFCA7E39}ProxyStubClsid32HKEY_CLASSES_ROOTInterface{0958C4C9-77B0-4AA8-9364-7886BFCA7E39}TypeLibHKEY_CLASSES_ROOTN.Cs4ClsidHKEY_CLASSES_ROOTTypeLib{C9F1C5A0-F3D8-48E2-8B8C-3E86B4CAC7E3}3.0 Quote