Search
 
 

Display results as :
 


Rechercher Advanced Search

Latest topics
» Request Info
Thu Sep 17, 2009 2:33 am by JeSTeR

» winagent.exe
Tue Sep 01, 2009 12:13 am by JeSTeR

» sissiBOT.exe
Mon Aug 31, 2009 11:42 pm by JeSTeR

» Posting Rules
Mon Aug 31, 2009 11:30 pm by JeSTeR

» There Are Hidden Posts Only Members Can Access
Sun Aug 23, 2009 1:05 am by JeSTeR

» IRC Server: IRC.HackersPlanet.Org
Wed Aug 19, 2009 9:42 pm by Shikamaru

» Rules For Posting
Wed Aug 19, 2009 9:35 pm by Shikamaru

» RootKit Downloads
Sun Jul 12, 2009 12:34 am by JeSTeR

» Anti-Rooting
Sun Jul 12, 2009 12:21 am by JeSTeR

Shopmotion


Navigation
 Portal
 Index
 Memberlist
 Profile
 FAQ
 Search

winagent.exe

Post new topic   Reply to topic

View previous topic View next topic Go down

winagent.exe

Post  JeSTeR on Tue Sep 01, 2009 12:13 am

* Submission details:
o Submission received: 31 August 2009, 18:26:26
o Processing time: 8 min 38 sec
o Submitted sample:
+ File MD5: 0x5EE26F43139A2CDB3A79A835574285A0
+ File SHA-1: 0x43933885866F58D3ABC8147CA79CB8F161957542
+ Filesize: 76,288 bytes
+ Alias:
# Trojan Horse [Symantec]
# Trojan-Downloader.Win32.Agent.chgu [Kaspersky Lab]
# Generic PWS.y [McAfee]
# Mal/Generic-A [Sophos]
# TrojanSpy:Win32/Mbdis.A [Microsoft]
# Trojan-Spy.Win32.Mbdis [Ikarus]
# Win-Trojan/Mbdis.76288 [AhnLab]

* The data identified by the following URLs was then requested from the remote web server:
o http://butirat.com/confirm.php?num=1240972&rev=26&code=1
o localhost
o http://freehotpornru.com/confirm.php?num=1240972&rev=26&code=1
o http://secure123.org/confirm.php?num=1240972&rev=26&code=1
o http://lnnskxvckj.net/confirm.php?num=1240972&rev=26&code=1
o http://butirat.com/confirm.php?num=1240972&rev=26&code=4
o http://freehotpornru.com/confirm.php?num=1240972&rev=26&code=4
o http://secure123.org/confirm.php?num=1240972&rev=26&code=4
o http://lnnskxvckj.net/confirm.php?num=1240972&rev=26&code=4
o http://butirat.com/job.php?num=24&rev=26
o http://freehotpornru.com/job.php?num=24&rev=26
o http://secure123.org/job.php?num=24&rev=26


BELOW IS WERE YOU WILL FIND IN ON YOUR SYSTEM!!!!!!!!!!
Fucking Company adWare!!!!!!!!!!!!!!!!
winagent.exe %System%\winagent.exe

JeSTeR
Admin

Age: 26
Posts: 132
Join date: 2008-09-28
Location: Earth

Back to top Go down

View previous topic View next topic Back to top


Permissions of this forum:
You cannot reply to topics in this forum