(21:08:51) BlackBerry: hebbo new.rar ... at ul.to - Free File Hosting, Free Image Hosting, Free Music Hosting, Free Video Hosting, ...
(21:09:00) BlackBerry: kannst du das mal checken?
(21:09:07) BlackBerry: opcodez sagt es sei ein istealer
(21:12:51) l0dsb: http://codepad.org/3cdSvLAk
(21:12:52) l0dsb: malware
Code:
.method private static hidebysig pinvokeimpl(kernel32 winapi) bool CreateProcess(class System.String, class System.String, native int, native int, bool, value class '???\r\n??????', native int, class System.String, value class '???\r\n??????'&, value class '???\r\n?????Å'&)
{
}
.method private static hidebysig pinvokeimpl(kernel32 winapi) bool WriteProcessMemory(native int, native int, unsigned int8[], unsigned int32, int32&)
{
}
.method private static hidebysig pinvokeimpl(ntdll winapi) bool NtUnmapViewOfSection(native int, native int)
{
}
.method private static hidebysig pinvokeimpl(kernel32 winapi) bool VirtualAllocEx(native int, native int, unsigned int32, value class '???\r\n?????ì', value class '???\r\n??????')
{
}
.method private static hidebysig pinvokeimpl(kernel32 winapi) bool VirtualProtectEx(native int, native int, unsigned int32, value class '???\r\n??????', unsigned int32&)
{
}
.method private static hidebysig pinvokeimpl(kernel32 winapi) bool GetThreadContext(native int, value class '???\r\n??????'&)
{
}
.method private static hidebysig pinvokeimpl(kernel32 winapi) bool SetThreadContext(native int, value class '???\r\n??????'&)
{
}
.method private static hidebysig pinvokeimpl(kernel32 winapi) unsigned int32 ResumeThread(native int)
{
}
^--- genau das, was RunPE macht.
Webpanel Link:
Login
Solltest du nicht antworten können. ICQ:
EDIT: ICQ Nummer wieder entfernt.