Quote:
Originally posted by shemgwapo+Jun 12 2007, 17:31--></span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (shemgwapo @ Jun 12 2007, 17:31)</td></tr><tr><td id='QUOTE'> <!--QuoteBegin--SwaDDie@Jun 12 2007, 16:46
It's trojan with keylogger function:
The program creates two files:
in my PC: C:\Windows\emcf.exe C:\Windows\isc.exe
in others: %sysdir%\Windows\emcf.exe
%sysdir%\Windows\isc.exe
It's connecting to:
mibicho.serveftp.com
And loggining with:
Username: Explodator
Password: juande
In the registry, that trojan add Run function in:
SOFTWARE\Microsoft\Windows\Currentv ersion\Run
With String or Key
svchost
Next it Copy uniqradar.exe to c:\windows\svchost.exe and run c:\windows\svchost.exe then take pop-up with message:
Press Ok before launching Silkroad client
Then loggint to the ftp and send SRo logs :)
---------------------------------------------------------
Respect to program author :)
---------------------------------------------------------
+k if helped
|
wow how'd you know about this? [/b][/quote]
Some brains in the head. :)
To Glavyana:
What was undetectable ?
If trojan, I think it was generated by something code.That code was coded by another code or smthing that :)
Or acc I mb spoted bad nick or smthing..
if you don't trust me, just run program go to
%sysdir%\windows\
there push anybutton and after that open svchost.log and you will see your pressed keystrokes.
Ok I will be in this forum :P
+k :)