Working UCE for Int-Server

07/24/2008 12:16 Mahatma#1
XeeT from HackThis.pl released a working uce...
cause u have to register on page be4 u can download and cause i try to prevent a few "noob threads" asking for an uce i uploaded the uce here again...
as i said....credits to XeeT or whoever made this uce^^
so hf and gl^^

Greeeeeetz
Mahatma

edit: idk if this are trojans or just rootkit, but it doesn't look good...i tried it and it worked...didn't thought that a mod of the poland forum would upload a trojan, so i didn't scan it..dl on your own risks!
07/24/2008 12:24 oMikrOn1331#2
Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.7.24.0 2008.07.24 -
AntiVir 7.8.1.11 2008.07.24 -
Authentium 5.1.0.4 2008.07.24 -
Avast 4.8.1195.0 2008.07.24 Win32:Agent-SJI
AVG 8.0.0.130 2008.07.24 -
BitDefender 7.2 2008.07.24 -
CAT-QuickHeal 9.50 2008.07.22 Trojan.Smalltro.hj
ClamAV 0.93.1 2008.07.24 Trojan.Delf.OWJ
DrWeb 4.44.0.09170 2008.07.24 Trojan.DownLoader.53869
eSafe 7.0.17.0 2008.07.23 Suspicious File
eTrust-Vet 31.6.5979 2008.07.24 -
Ewido 4.0 2008.07.23 Trojan.Lmir.ayr
F-Prot 4.4.4.56 2008.07.22 -
F-Secure 7.60.13501.0 2008.07.24
Fortinet 3.14.0.0 2008.07.24 -
GData 2.0.7306.1023 2008.07.24 -
Ikarus T3.1.1.34.0 2008.07.24 Trojan.Click
Kaspersky 7.0.0.125 2008.07.24 -
McAfee 5345 2008.07.23 -
Microsoft 1.3704 2008.07.24 -
NOD32v2 3293 2008.07.23 -
Norman 5.80.02 2008.07.23 -
Panda 9.0.0.4 2008.07.24 Suspicious file
PCTools 4.4.2.0 2008.07.24 -
Prevx1 V2 2008.07.24 Malicious Software
Rising 20.54.32.00 2008.07.24 -
Sophos 4.31.0 2008.07.24 Troj/CheatEng-A
Sunbelt 3.1.1536.1 2008.07.18 VIPRE.Suspicious
Symantec 10 2008.07.24 -
TheHacker 6.2.96.387 2008.07.23 -
TrendMicro 8.700.0.1004 2008.07.24 -
VBA32 3.12.8.1 2008.07.23 Trojan.Click
ViRobot 2008.7.24.1309 2008.07.24 -
VirusBuster 4.5.11.0 2008.07.23 -
Webwasher-Gateway 6.6.2 2008.07.24 Win32.Malware.gen (suspicious)

WTF
07/24/2008 12:26 oMikrOn1331#3
Voll mit Trojanern !!!!!!!!!!!!!!!
07/24/2008 12:30 doener#4
Sei ruhig,wenn man keine Ahnung hat.

Ich schaus mir nacher mal mit Sandbox an ob hidden sending von der uce ausgeht.
07/24/2008 19:47 mercenarioo7#5
Quote:
File:ISO-8859-1__DAEngine.rar
Status: INFECTED/MALWARE
MD5: 4beecabfb99ac5e2bb843d0f1555c1af
Packers detected:-
Scan taken on 24 Jul 2008 17:41:40 (GMT)
A-Squared
Found nothing
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found Win32:Agent-SJI
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found Trojan.Delf.OWJ
CPsecure
Found SpamTool.W32.Agent.v
Dr.Web
Found Trojan.DownLoader.53869
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Ikarus
Found Trojan.Click, Virus.Win32.Agent.aj, Trojan.Rootkit, Trojan-Downloader.JS.Feebs, Trojan-Downloader.21752
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Sophos Antivirus
Found Troj/CheatEng-A, Sus/UnkPacker (probable variant)
VirusBuster
Found nothing
VBA32
Found Trojan.Click, Trojan.DownLoader.53869, Trojan.DownLoader
*
07/25/2008 14:33 oMikrOn1331#6
und doener was ist jetzt????
07/25/2008 21:07 exeduz#7
Die UCE ist clean Mikron.
07/25/2008 22:17 carpulli#8
bullshittttttttttttttttt this UCE does not work, even with rootkit to hide it... the game still closes after a few seconds !

i tried every other UCE + rootkit on this forum and none worked
07/25/2008 22:21 StickyIcky#9
polacken halt XD
07/25/2008 22:24 doener#10
Sorry^^ hab noch andere Sachen zu tun außer am Pc zu sitzen :).

Ehm ja hab nichts auffälliges gefunden ,hab sie aber nicht getestet hab kein int kal.

^^
07/25/2008 22:44 zadkine#11
i think its clean not thet good in german:P but if it whas infected the link would be deleted :P

and i trust you Mahatma
07/25/2008 22:44 carpulli#12
nothing works i think at the moment..

MHS4.0.0.13 is working at the moment, but i am not so sure on how to use it...

you can find it here
[Only registered and activated users can see links. Click Here To Register...]

anyone post a tut on how to use it ??

EDIT: KalOwnline works with rootkit (undetected on Int server)

no problem now you guys back 2 hackin :)~

KalOwnline: [Only registered and activated users can see links. Click Here To Register...]