It's coded in VB6 (verified with PEID)
found that it was crypted, this was when i opened it with notepad :cool:
Code:
C : \ c r y p t o r \ P r o j e c t 1 - C o p y ( 7 ) \ P r o j e c t 1 . v b p
anubis said: OMG 7 RED FLAGS AND IT EVEN JOINS IRC:
Code:
Summary:
- Autostart capabilities:
This executable registers processes to be executed at system start.
This could result in unwanted actions to be performed automatically.
- Changes security settings of Internet Explorer:
This system alteration could seriously affect safety surfing the World
Wide Web.
- Creates files in the Windows system directory:
Malware often keepscopies of itself in the Windows directory to stay
undetected by users.
- Joins IRC Network:
The executable connects to an IRC network, most probably functioning as
a zombie in a botnet.
- Performs File Modification and Destruction:
The executable modifiesand destructs files which are not temporary.
- Spawns Processes:
The executable produces processes during the execution.
- Performs Registry Activities:
The executable reads and modifies registry values. It also creates and
monitors registry keys.
Virustotal totally FLIPPED and said: You got to be kidding me?!
Code:
Result: 27/40 (67.5%)
Btw,, it creates a file named C:\WINDOWS\system32\win32.exe
and the coder must be one hell of a skiddie, cuz it connects with a LAN local IP: 192.168.0.1