Hacking and more...
HaCkinG CulT
Lista Forumurilor Pe Tematici
Hacking and more... | Reguli | Inregistrare | Login

POZE HACKING AND MORE...

Nu sunteti logat.
Nou pe simpatie:
lutsen Profile
Femeie
24 ani
Cluj
cauta Barbat
24 - 48 ani
Hacking and more... / Virus/Trojan / Win32.saburex.a Moderat de Shocker
Autor
Mesaj Pagini: 1
eXe
Old School Member

Din: romania
Inregistrat: acum 17 ani
Postari: 451
Care imi poate da mai multe informatii despre acest virus ce face el mai exact sistemului ca am avut cam multe executabile infectate cu acest virus

_______________________________________
Dacă pare uşor, e greu. Dacă pare greu, e absolut imposibil.

pus acum 17 ani
   
hackedss
Elite Member

Inregistrat: acum 17 ani
Postari: 858


Code:

Threat Encyclopaedia
    Print this pageSend
Win32/Saburex.A
Type of infiltration:    virus 
Size:    approximately 13 kB 
Affected platforms:    Microsoft Windows 
Signature database version:    1921 
Short description:    Win32/Saburex.A is a parasitic virus that is able to steal passwords and other sensitive information. 

Installation

The following file is dropped in the %system% folder:

        ole16.dll

Size of the file is 17920 B. In order to be executed on every system start, the virus sets the following Registry entries:

[HKEY_CLASSES_ROOTCLSID{00021401-0000-0000-C000-000000000046}InProcServer32]
default = "ole16.dll"
"ThreadingModel" = "both"

 

If that fails, the following entries are set instead:

[HKEY_CURRENT_USERSoftwareClassesCLSID{00021401-0000-0000-C000-000000000046}InProcServer32]
default = "ole16.dll"
"ThreadingModel" = "both"

 

Executable files infection

The virus searches for executables on local drives. Infection is attempted only if an executable is not in a folder that contains one of the following strings in its name:

        documents and
        music
        program files
        win
        _restore

Several other criteria are applied when choosing a file to infect. The virus overwrites code in the first section of the host. The original code is compressed in a CAB archive and appended to the file. The original host executable can be reconstructed when an infected file is run. Another CAB archive containing the DLL library is appended as well.

Information stealing

The virus collects various information when a certain application is being used. The data is saved in the following Registry key:

HKEY_CURRENT_USERSoftwareMicrosoftMediaPlayerLicences

 

The virus can send the information to a remote machine. The HTTP protocol is used.



_______________________________________



pus acum 17 ani
   
Shocker
Super Moderator

Din: localhost
Inregistrat: acum 18 ani
Postari: 2084
Uite aici si un Removal Tool 

_______________________________________
ShockingSoft is back
Freakz only
Comics of the day

pus acum 17 ani
   
Pagini: 1  

Mergi la