A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #4497  by Xylitol
 Mon Jan 17, 2011 12:32 am
Attachments
see archive comment for password
(28.66 KiB) Downloaded 80 times
see archive comment for password
(51.47 KiB) Downloaded 92 times
 #4647  by Xylitol
 Sun Jan 23, 2011 12:16 am
Attachments
see archive comment for password
(28.72 KiB) Downloaded 77 times
see archive comment for password
(332.8 KiB) Downloaded 70 times
see archive comment for password
(53.12 KiB) Downloaded 87 times
 #4913  by Xylitol
 Sun Feb 06, 2011 11:44 am
new loc: hXXp://pepka-master2012.narod2.ru/xxx_video.avi.exe
Code: Select all
00406B81  |.  E8 62EAFFFF   CALL 004055E8           ; \GetWindowTextA
serial must start with "000" someone can confirm i dont really understand how work the regitration schem ?
Image

Image

Image
Attachments
see archive comment for password
(102.54 KiB) Downloaded 66 times
 #5025  by Xylitol
 Sat Feb 12, 2011 2:38 pm
Attachments
see archive comment for password
(114.28 KiB) Downloaded 59 times
 #5080  by Xylitol
 Thu Feb 17, 2011 1:47 pm
Attachments
See archive comment for password

xxx_video_55843.avi.exe.vir
xxx_video_55843.avi_unpacked.exe.vir

(109.52 KiB) Downloaded 57 times
 #5085  by Xylitol
 Thu Feb 17, 2011 10:58 pm
Attachments
see archive comment for password
(171.79 KiB) Downloaded 57 times