Attachments
(152.11 KiB) Downloaded 46 times
A forum for reverse engineering, OS internals and malware analysis
ikolor wrote:is not new butI don't know the name of this one :/
https://www.virustotal.com/en/file/a540 ... 467144714/
CRT_RENAMER.OBJ
CRT_RENAMER.JBO
Could not rename '%s'
File '%s' renamed to '%s'
Enter an integer, a real number, a character and a string :
Not all fields were assigned
gtty
do not use win10
Ivanovo Volkovo "%s"
Hilary Clinton "%s"
computer
Unicode
%lc %ls
%lc %ls
%lc %.4ls
%lc %#.2ls
Enter a string %ls
Suck my dick! You are fucking AV vendors!
eerrdd
therefore, we need to find the solution
%s?command=dl&id=%s
POST
%s?command=log&id=%s
%s?command=version&id=%s&soft_ver=%s&win_ver=%s
http
%s?command=getbackconnect&id=%s
%s?command=ghl&id=%s
output.log
firewall add allowedprogram "%s" "%s" ENABLE
netsh
PB_SN_MUTEX_GL_F348B3A2387
PB_MAIN_MUTEX_GL_63785462387
PB_SCH_MUTEX_GL_A58B78398f17
http://uplyoufilterfa.com/uplod.php
http://foupdownhelp.com/desk.php
CScriptWorker::LoadPage InternetOpen error %d
CScriptWorker::LoadPage InternetConnect error %d
GET
CScriptWorker::LoadPage HttpOpenRequest error %d
CScriptWorker::LoadPage HttpSendRequest error %d
CScriptWorker::LoadPage InternetReadFile error %d
http://
https://
?command=getid
?command=getip
%s?command=update&id=%s&ip=%s&port=%d
Ping received
Windows 2000
Windows XP
Windows XP Professional x64 Edition
Windows Home Server
Windows Server 2003
Windows Server 2003 R2
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 8
Windows Server 2012
Windows 8.1
Windows Server 2012 R2
Windows 10
Windows Server 2016
Windows ver %d.%d