zLoader v.1.0

3apa3a

Member
Messages
9
Reputation
1
Reaction score
1
Points
3
Greetings, brothers!
I want to present you a new loader - (zLo)ader v.1.0


FEATURES:


• Completely written in MASM (maximally reduced size and speed of execution)

• Size of build 10 kB (non-crypted and non-packed)

• Stable work in Win2000/XP/2003/Vista/Se7en

• Work in restricted accounts (even guest)

• Bypass UAC (Vista/Se7en) and security system (not notify that the file has no digital signature)

• All string data is encrypted and decrypted by measure performance, and then immediately cleaned

• Dynamic imports by hashes from the function names

• Antidebugging

• Loader may be crypted and packed almost any software without loss of efficiency

• Control re-running (if the loader does not fetch the first time, it deletes itself)

• Unvisible in the list of runned processes

• Allows you to download unlimited number of files of any size

• Encrypt links to download files from the script (reference files are not conspicuous in traffic)

• Download and run files occurs immediately. Next step - delete itself

• Bypass popular firewalls and proactive protection (the default settings, the default setting)
without any interference in their work

Tested on the following products:
Agnitum Outpost 7
Kaspersky Internet Security 2010
Dr.Web 6 Security Space
ESET NOD32 Smart Security 4.2
PANDA Global Protection 2010
Trend Micro Internet Security Pro 2010
AVS Firewall 2.1.1.238
PC Tools Internet Security 2010
AVG Internet Security 9 - shows the alert when running the downloaded files,
but the files will still run
F-Secure Internet Security 2010 - not be detected by network activity,
but SOMETIMES when you run the downloaded files
shows the alert and they do not run :(

• Admin panel implemented without MySQL (Quick and easy setup, can withstand heavy loads)

• Ability to loads of country

• Comprehensive statistics (how many tasks received, how many files are loaded, how many really started)

• Create an unlimited number of tasks

• Each task can specify an unlimited number of links to files


PRICES:


zLoader 333 wmz
Cleaning 33 wmz
Change URL to admin panel 66 wmz


CONTACTS:


ICQ: 5335-6-one-32
Jabber: [email protected]


 

3apa3a

Member
Messages
9
Reputation
1
Reaction score
1
Points
3
[zLo]ader v.1.0.5 - resident loader


The difference from v.1.0:


• Bot is now installed in the system and knock in the admin panel with adjustable interval

• Encrypts his configuration by RC4 with 32-bit key, unique for each infected machine

• Rewrote the primary inject a trusted process. This allowed further reduce the size of bot

• The size of the build 10 kB (non-crypted/non-packed)

• Does not contain string data

• Hides its presence in the system in Ring3 (registry / disk / process)

• As shown by tests - to the list traversal added the following
products (the default settings, the default settings):
Mcafee Internet Security 2010
Norton Internet Security 2010
Sunbelt Personal Firewall 4

• Ability to use a backup admin, if the first is unavailable

• Change the admin. Now shows the full article on the bots, the number of bots online, the number of bots online yesterday,
The number of new boats today, the number of bots, all statistics OS bots, the bot checks the receiving jobs
to avoid duplicates



BRIEF OF THE RESIDENT:


After the installs / rebut the bot checks the connections to connect to Internet knocks on the main admin panel
and receives from it the interval between knocks. If its did not work - bot knocking on the backup admin panel.
If the backup admin is not available - bot stops all its threads, and removes the hooks, deletes itself.
This is done in order not to go into an infinite loop when falling two admin panels
and in case of repeated punching by exploit version of the bot with the configuration of other adminok could run
and function normally (control of reinfection).
Then the bot as in v.1.0 gets the job (if it exists, and bot it does not do), it performs
and waits for the next knock to replicate all of this first



 

3apa3a

Member
Messages
9
Reputation
1
Reaction score
1
Points
3
Check for AV (1/32)
http://scan4you.biz/result.php?id=83085_2i49f

---------- Сообщение добавлено в 06:21 PM ---------- Предыдущее сообщение размещено в 05:26 PM ----------

NEW PRICES:
[zLo]ader 333 wmz
Cleaning 15 wmz
Rebild for other admin URLs free
 
Top