Code: Select all
http://www.virustotal.com/file-scan/rep ... 1295868598 http://cs-download-16.info/setup.exe
Attachments
(7.17 KiB) Downloaded 46 times
A forum for reverse engineering, OS internals and malware analysis
http://cs-download-16.info/setup.exe
markusg wrote:trojan downloader written on VB and providing fantastic features:Code: Select allhttp://www.virustotal.com/file-scan/rep ... 1295868598http://cs-download-16.info/setup.exe
Wireshark
tcpview
MSASCui
msmpeng
asdc.exe
asdc
alxx.exe
alxx
alx.exe
alx
avcx.exe
avcx
nvsvc32.exe
NVIDIA driver monitor
winnew.exe
Software\Microsoft\Windows NT\CurrentVersion\Windows
load
ranga.exe
panga.exe
Software\Microsoft\Windows\CurrentVersion\Run
Service Noits
SERVICES.EXE
WINLOGON.EXE
hidserv.exe
explorer.exe
netsh firewall add allowedprogram %s 1 ENABLE
dbghelp.dll
SbieDll.dll
currentuser
vmware
honey
sandbox
ntdll.dll
ZwQueryInformationProcess
ZwQuerySystemInformation
C:\sample.exe
T/host.txt
compartetuspelis.in
\System32\drivers\etc\hosts
open
ERROR
.?AV_com_error@@
.?AVtype_info@@
KERNEL32.DLL
ADVAPI32.dll
MSVCRT.dll
ole32.dll
OLEAUT32.dll
SHELL32.dll
SHLWAPI.dll
USER32.dll
WSOCK32.dll
Module32First
CreateToolhelp32Snapshot
GetWindowsDirectoryA
Process32Next
Process32First
GetModuleFileNameA
GetModuleHandleA
CreateProcessA
GetTempPathA
GetTickCount
CopyFileA
ExitProcess
ReleaseMutex
WriteFile
CreateFileA
CreateThread
SetFileAttributesA
CreateMutexA
GetCurrentProcess
GetProcAddress
GlobalUnlock
GlobalLock
GlobalAlloc
ExitThread
GetVersionExA
GetVolumeInformationA
GetDriveTypeA
GetLogicalDriveStringsA
Sleep
DeleteFileA
Module32Next
LocalFree
WideCharToMultiByte
MultiByteToWideChar
lstrlenW
GetStartupInfoA
lstrlenA
InterlockedDecrement
OpenProcess
TerminateProcess
GetLastError
CloseHandle
RegQueryValueExA
RegDeleteValueA
RegOpenKeyExA
RegCreateKeyA
RegSetValueExA
RegCreateKeyExA
GetUserNameA
RegCloseKey
_controlfp
__dllonexit
_onexit
_stricmp
wcslen
_CxxThrowException
__set_app_type
__p__fmode
__p__commode
_adjust_fdiv
__setusermatherr
_initterm
__getmainargs
_acmdln
exit
_XcptFilter
_exit
isalpha
islower
isupper
isdigit
_ftol
??1type_info@@UAE@XZ
ceil
toupper
_except_handler3
fprintf
remove
rename
fgets
strncpy
_snprintf
strcpy
free
realloc
sprintf
malloc
__CxxFrameHandler
??3@YAXPAX@Z
??2@YAPAXI@Z
strncmp
strcmp
strcat
strstr
fclose
fwrite
fopen
strtok
strlen
memset
strtol
rand
srand
time
strrchr
CoInitialize
CoCreateInstance
CoUninitialize
SHGetSpecialFolderLocation
SHGetPathFromIDListA
ShellExecuteA
PathAppendA
ShowWindow
EmptyClipboard
wsprintfA
CharLowerA
CloseClipboard
OpenClipboard
VkKeyScanA
keybd_event
SetFocus
SetForegroundWindow
BlockInput
SetClipboardData
markusg wrote:Adobe Photoshop CS5 -EXTENDED- Keygen.exePacked by UPX VB dropper for VB.NET trojan. While work extracts it and runs.
http://www.virustotal.com/file-scan/rep ... 1298897237