2012/08/08

FakeAV - Windows Antivirus Release


MD5: 960f698531cd8d92298e4e61f1bd0e1b 
Size : 2405888 Bytes 
Unlock code:  0W000-000B0-00T00-E0020 

Values Created 
CU - Current User
CU\Software\Microsoft\Windows\CurrentVersion\Run\Inspector "C:\Documents and Settings\User
\Application Data\Protector-megc.exe
CU\Software\Microsoft\Windows\CurrentVersion\Settings\net "2009-1-9_5" 
CU\Software\Microsoft\Windows\CurrentVersion\Settings\UID "nyvkelapbt"
Directories Created : 
C:\Documents and Settings\User\Application Data\Macromedia
C:\Documents and Settings\User\Application Data\Macromedia\Flash Player
C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\macromedia.com
C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\macromedia.com\support
C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\macromedia.com
\support\flashplayer
C:\Documents and Settings\User\Application Data\Macromedia\Flash Player\macromedia.com
\support\flashplayer\sys 
Files Created :
C:\Documents and Settings\User\Application Data\Macromedia\Flash Player
\macromedia.com\support\flashplayer\sys\#local\settings.sol 
C:\Documents and Settings\User\Application Data\Protector-megc.exe
C:\Documents and Settings\User\Local Settings\Temporary Internet Files
\Content.IE5\8DIFWPAR\galaint.inforeleasestat[1].htm  
Processes Created :
Protector-megc.exe and mshta.exe 
DOWNLOAD SAMPLE 
http://www.mediafire.com/?nn9a9z1i89k31m6 
Password: malwaresniper 
Members www.malware-sniper.blogspot.com no responsibility for any damage caused by malware. It is used at your own risk!   


No comments:

Post a Comment