12.05.2013, 17:20
tachion napisał(a):Anonymous Network napisał(a):PurityScan.C
Kod:Created a service named: bizboan
Created process: C:\Program Files\Bizboan\bizsvc.exe, "C:\Program Files\Bizboan\bizsvc.exe" i, C:\Program Files\Bizboan
Created process: null, \DelUS.bat, \
Created process: null, C:\Program Files\Bizboan\bizstartup.exe -start, null
Defined file type created: C:\Program Files\Bizboan\bizboan.exe
Defined file type created: C:\Program Files\Bizboan\BizMon.exe
Defined file type created: C:\Program Files\Bizboan\bizstartup.exe
Defined file type created: C:\Program Files\Bizboan\bizsvc.exe
Defined file type created: C:\Program Files\Bizboan\option.ini
Defined file type created: C:\Program Files\Bizboan\uninst.exe
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\bizboan\DisplayName = bizboan =_D_
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\bizboan\ErrorControl = 00000001
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\bizboan\ImagePath = C:\Program Files\Bizboan\bizsvc.exe
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\bizboan\Start = 00000002
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\bizboan\Type = 00000010
GET http://www.msme.co.kr/bizboan/macaddr_chk?mac=080027e1f647 HTTP/1.1
User-Agent: BIZBOAN
Host: www.msme.co.kr
Pragma: no-cache
Cookie: ci_session=vjITC5DmlUqDM%2B9TKWnuXqm%2B2gMDsLoBR5XKcWrSUtm98bNnnXbH4oPUVF4vU835NGroHy%2F8qxFS4jfjQhWGLtmcrveRCw7Oswh55bJWAdfmV5Y8peuB6Q5anK4Yqd7%2BB%2FEgA6brobyDIwhoHmNicOP4G3BBZS4phwyho%2B8mCgw2oMemoAdSkT5HwUGD6kMpAhX7KK06alW3Y8jj%2B2RvP5LvLXddr2zhGpb5i%2FMeaGDo20J56NsznVK7G4uLEr2glWk%2BoDic5ntSZn9w%2FnS5nG%2BMY1NIpXaWAlPcHAradtk%3D
Rogue, add malware bytes .
Anonymous is here for the people! EXPECT US.