A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #6360  by markusg
 Tue May 17, 2011 1:39 pm
have a look in the rogue /fake av topic im sure there was an sample posted. :-)
 #6390  by bitx
 Wed May 18, 2011 10:38 am
Windows System Tasks

Image
Attachments
pass=malware
(1.67 MiB) Downloaded 70 times
Last edited by EP_X0FF on Fri May 27, 2011 3:18 pm, edited 1 time in total. Reason: title edited
 #6393  by bitx
 Wed May 18, 2011 12:34 pm
Essential Cleaner

Image
Attachments
pass=malware
(339.62 KiB) Downloaded 74 times
Last edited by EP_X0FF on Fri May 27, 2011 3:18 pm, edited 1 time in total. Reason: title edited
 #6408  by Xylitol
 Wed May 18, 2011 8:01 pm
first version of Essential Cleaner (not posted due to my lake of time)

17/42 >>40.5%
http://www.virustotal.com/file-scan/rep ... 1305748634

with the same anti vmware on board:
Image

registration schem (double check as usual, TextBox/Clipboard):
Image

serials dump:
Code: Select all
ECX=0165C328, (ASCII "EEDA-S0DF5-GS5E0-FG14S-2DF8G")
ECX=0165C328, (ASCII "EEDA-JUYH3-24GHJ-HGKSH-FKLSD")
ECX=0165C328, (ASCII "EEDA-89OF7-7324R-5SAD4-TG68U")
ECX=0165C328, (ASCII "EEDA-HFVDR-9844O-U54DA-5TBSC")
ECX=0165C328, (ASCII "EEDA-G8FB6-1V87S-DRT1S-63SRG")
ECX=0165C328, (ASCII "EEDA-4BGY2-JY4KO-IT98Y-7HJ43")
ECX=0165C328, (ASCII "EEDA-5D1V2-XB0D5-JT1TY-97DS3")
ECX=0165C328, (ASCII "EEDA-F40SA-1ER5H-4FG5D-F8412")
ECX=0165C328, (ASCII "EEDA-SERFH-2642S-F04SD-64FG1")
ECX=0165C328, (ASCII "EEDA-S0DF5-GS5E0-FG14S-2DF8G")
ECX=0165C328, (ASCII "EEDA-452S3-ER00F-TSE35-S8FSD")
ECX=0165C328, (ASCII "EEDA-FGS5D-649RG-4S53D-412SF")
ECX=0165C328, (ASCII "EEDA-4TS8R-D6F5D-4JH8T-U4JK5")
ECX=0165C328, (ASCII "EEDA-2AE32-1VFC2-B6894-G67YU")
ECX=0165C328, (ASCII "EEDA-P9685-4H41A-DSW3A-2R64T")
ECX=0165C328, (ASCII "EEDA-5SRTS-AEHUF-YA54S-D6F35")
ECX=0165C328, (ASCII "EEDA-A1SDF-RY4E8-7U98D-F1GB2")
ECX=0165C328, (ASCII "EEDA-A1SDF-6AS4D-RF5RE-79G84")
ECX=0165C328, (ASCII "EEDA-TTUYJ-7UO54-G561H-J1D6F")
ECX=0165C328, (ASCII "EEDA-G84H6-S854F-79ZA8-W4ERS")
ECX=0165C328, (ASCII "EEDA-6W954-FX65B-41VDF-8G4JI")
ECX=0165C328, (ASCII "EEDA-U94KO-LF4G4-1V8S1-2CRFE")
ECX=0165C328, (ASCII "EEDA-TGN15-RFF29-AASDJ-ASD65")
ECX=0165C328, (ASCII "8812702347")
ECX=0165C328, (ASCII "7713712456")
ECX=0165C328, (ASCII "6614722565")
ECX=0165C370, (ASCII "EEDB-ADEEF-FEADD-2FEAA-3EFA7")
ECX=0165C370, (ASCII "EEDB-ADEEE-3ADEF-4A78C-32768")
ECX=0165C370, (ASCII "4432125899")
ECX=0165C370, (ASCII "5532225898")
ECX=0165C370, (ASCII "6632325897")
Attachments
See archive comment for password
(415.64 KiB) Downloaded 63 times
 #6411  by bitx
 Thu May 19, 2011 12:55 pm
Windows Repairing System

Image
Attachments
pass=malware
(1.68 MiB) Downloaded 56 times
Last edited by EP_X0FF on Fri May 27, 2011 3:19 pm, edited 1 time in total. Reason: title edited
 #6432  by Xylitol
 Fri May 20, 2011 9:23 am
Attachments
See archive comment for password
(1.66 MiB) Downloaded 94 times
Last edited by EP_X0FF on Fri May 27, 2011 3:19 pm, edited 1 time in total. Reason: title edited
 #6435  by bitx
 Fri May 20, 2011 12:32 pm
Windows Safeguard Utility

Image
Attachments
pass=malware
(1.67 MiB) Downloaded 69 times
Last edited by EP_X0FF on Thu Jun 02, 2011 7:16 am, edited 2 times in total. Reason: title edited
 #6448  by Xylitol
 Fri May 20, 2011 11:12 pm
Windows Recovery & Security Solution 2011

Image

serial calc in
Code: Select all
004303DE    E8 8249FEFF     CALL 00414D65 
regged
Image

hxxp://www.securitysolution2011corp.com/faq/
hxxp://www.securitysolution2011corp.com/support/
Attachments
See archive comment for password
(4.79 MiB) Downloaded 100 times
See archive comment for password
(699.64 KiB) Downloaded 70 times
Last edited by EP_X0FF on Fri May 27, 2011 3:22 pm, edited 2 times in total. Reason: title edited
 #6468  by EP_X0FF
 Sun May 22, 2011 2:22 am
@deco11

Serial posted in Xylitol blog. Thank you for reposting it here (as something unknown) and say goodbye to this forum.
  • 1
  • 11
  • 12
  • 13
  • 14
  • 15
  • 34