[Release]GreYFoX NoDC 1.141 Beta 2 (Memory Patch)

01/28/2008 15:53 fast2die#31
U Hack Any One I Blow Ur Balls UP =)
01/28/2008 21:44 bone80#32
Quote:
Originally Posted by antares View Post
what you are not going to obtain is my PW!!;)
if your head wasn't up your ass so far
maybe then you would realize who ur doubting:cool:
01/29/2008 14:58 lady_slasher#33
Quote:
Originally Posted by antares View Post
nformation about the Sohanad Worm(detected in Analysis of the file GreYFoX_NoDC_1.141_Beta_2_Memory_):

Sohanad is a worm. The worm will infect Windows systems and spreads through Yahoo! Messenger, a popular instant messaging application.

The worm arrives as a downloaded file via Yahoo! Messenger.

Upon execution, this worm copies itself as SVHOST32.EXE and SVHOST.EXE in the Windows folder.

The worm modifies registry at the following location to load itself during each startup.

HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentV ersionRun

It also creates the following registry keys to modify the settings of Yahoo! Messenger.

HKEY_CURRENT_USERSoftwareYahoopagerViewYMSGR_buzz
HKEY_CURRENT_USERSoftwareYahoopagerViewYMSGR_Launc hcast

The worm also modifies the registry to disable Registry Editor and Task Manager.

It also changes the Internet Explorer (IE) home page to;

[Only registered and activated users can see links. Click Here To Register...]

This worm propagates via Yahoo! Messenger by sending an instant message to all the contacts of an active user. This message contains a link to a remote copy of itself. When the recipient clicks the link, a copy of this worm is downloaded and executed on the recipients' system.

The details of the message sent out by this worm are;

Do you realize who is in this image: http://{BLOCKED}coolpics.net/who.jpg . Just think for a moment and tell me soon ;))
:D who is beside you in this pic [Only registered and activated users can see links. Click Here To Register...] so good-looking
:( the page cannot be displayed http://{BLOCKED}coolpics.net/error.jpg Something was wrong !!! Check it again and tell me later. THanks
Images shot in Iraq _ The war will never end http://{BLOCKED}coolpics.net/Iraqwar.jpg << :(
Miss World 2006: http://{BLOCKED}coolpics.net/MissWorld.jpg !! <<
oh my god , i've won a 20000 usd lottery :O http://{BLOCKED}coolpics.net/mylottery.jpg <<

It also attempts to connect to the following website to download and execute some malicious files.

http://{BLOCKED}vey-sales.com/ipn/transactions/en.exe
http://{BLOCKED}vey-sales.com/ipn/transactions/link-en.exe

The worm tries to terminate some of the security related processes.

This worm first appeared on November 12, 2006.

Blueball Other names of Sohanad Worm:

This Worm is also known as WORM_SOHANAD.AE.

wer the same side dude............
thanks for the info....
like what ive said... too many abuser in this forum....
to all of you guys.. be suspicious..... use the clean one....
^,..,^
01/29/2008 15:26 lady_slasher#34
OK GUYS....
Ill give you some additonal information about SOHANAD Virus...
Some of you didnt know this kind of Virus.... how dangerous this kind of VIRUS SONAHAD
Ofcourse he doesnt want our account in SRO.. the QUESTION IS....... " is the SRO account he want from us???????? LOL
how about our personal info??.....
how about our bank account???? credit card number?? etc??.....
ahahahahahahahahahahahahahahahahahahahahahaha..... .. F*CK YOU ALL........
S I G H......... S I G H.........

SEE AND READ IT........ THEN LET YOUR HEART JUDGE......

CLICK HERE AND YOULL SEE...( INFO. OF SOHANAD VIRUS)
[Only registered and activated users can see links. Click Here To Register...]
01/29/2008 16:13 cotta#35
Lady Slasher
dont judge him like that
we all of us know who is GreyFox
all we can do it scan his client and then debate his release
but try to understand that is a tool that make all the hell of that

and if you research for his release clients ,you will see all of them 99% clean .
01/30/2008 01:26 InvincibleNoOB#36
lady_slasher stop being a paranoid!
The program is made on Autoit3 thats all.
If you want a sample,check this one

unpacked: [Only registered and activated users can see links. Click Here To Register...]
packed ~ armadillo 5.2: [Only registered and activated users can see links. Click Here To Register...]

Stupid AVs -.-
11/22/2008 15:13 pleb123#37
just followed your tutorial and now i cant even load up silkroad
11/22/2008 15:26 John Dread#38
dude please read the title: [Release]GreYFoX NoDC 1.141 Beta 2 (Memory Patch)

#closed