A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #4489  by EP_X0FF
 Sun Jan 16, 2011 3:19 pm
Offtopic post about Windows load order moved to separate thread
 #4494  by EP_X0FF
 Sun Jan 16, 2011 5:44 pm
Porno Media Module (Adult Ban, sub family or lockers)

remembers me this http://forum.sysinternals.com/trojan-ra ... 22054.html

Crap drops to %Documents and Settings%\All Users\Media (XP)

Image

http://www.virustotal.com/file-scan/rep ... 1295197172

Unblock, two stages:

1. 28527548
2. 35676549

Or kill it with help of any non standard taskmanager.

Image
Image

In attach both original and unpacked.
Attachments
pass: malware
(129.27 KiB) Downloaded 70 times
 #4505  by nullptr
 Mon Jan 17, 2011 10:45 am
xhandsome wrote:"see archive comment for password" ?
I don't know how to get the password, Please guide for me how to get the pass word,
thanks
Depends on what archive app you use, but for the archives in question the pw is xylibox
 #4515  by EP_X0FF
 Mon Jan 17, 2011 3:28 pm
Thread split.

All Lock Em All related discussion moved to Trojan.Winlock - Lock Em All thread.
 #4615  by EP_X0FF
 Fri Jan 21, 2011 2:56 pm
Thread split, BlueTrash and Homoblocker discussion moved to special separate topic. This was done because both lockers constantly updating - changing hardcoded unblock keys. There is no need to post them again and again (because they are nothing new except codes), as in fact all what required - tel number, unblock code, VT report (if available) and malware source (if available).
 #4893  by EP_X0FF
 Sat Feb 05, 2011 3:31 pm
Thread split.

Delphi pornoblocker (virtual keyboard) stuff moved to dedicated topic
  • 1
  • 2
  • 3
  • 4
  • 5
  • 9