Hacking and more...
HaCkinG CulT
|
Nou pe simpatie: Lorena13 Profile
 | Femeie 24 ani Bucuresti cauta Barbat 26 - 40 ani |
|
|
Hacking and more...ReguliInregistrareLoginPozeNu sunteti logat. Lista Forumurilor Pe Tematici
|
| #1 |
eXeOld School MemberDin: romania
Postari: 451
|
|
Care imi poate da mai multe informatii despre acest virus ce face el mai exact sistemului ca am avut cam multe executabile infectate cu acest virus 
_______________________________________ Dacă pare uşor, e greu. Dacă pare greu, e absolut imposibil. www.google.ro
|
|
| |
|
| #2 |
|
|
Code:
Threat Encyclopaedia
Print this pageSend
Win32/Saburex.A
Type of infiltration: virus
Size: approximately 13 kB
Affected platforms: Microsoft Windows
Signature database version: 1921
Short description: Win32/Saburex.A is a parasitic virus that is able to steal passwords and other sensitive information.
Installation
The following file is dropped in the %system% folder:
ole16.dll
Size of the file is 17920 B. In order to be executed on every system start, the virus sets the following Registry entries:
[HKEY_CLASSES_ROOTCLSID{00021401-0000-0000-C000-000000000046}InProcServer32]
default = "ole16.dll"
"ThreadingModel" = "both"
If that fails, the following entries are set instead:
[HKEY_CURRENT_USERSoftwareClassesCLSID{00021401-0000-0000-C000-000000000046}InProcServer32]
default = "ole16.dll"
"ThreadingModel" = "both"
Executable files infection
The virus searches for executables on local drives. Infection is attempted only if an executable is not in a folder that contains one of the following strings in its name:
documents and
music
program files
win
_restore
Several other criteria are applied when choosing a file to infect. The virus overwrites code in the first section of the host. The original code is compressed in a CAB archive and appended to the file. The original host executable can be reconstructed when an infected file is run. Another CAB archive containing the DLL library is appended as well.
Information stealing
The virus collects various information when a certain application is being used. The data is saved in the following Registry key:
HKEY_CURRENT_USERSoftwareMicrosoftMediaPlayerLicences
The virus can send the information to a remote machine. The HTTP protocol is used. |
_______________________________________


|
|
| |
|
| #3 |
ShockerSuper ModeratorDin: localhost
Postari: 2084
|
|
|
| |
|