Dom Nov 28, 2010 9:19 pm
Done:
[100%] - Unique Polymorphic Server on every Compile.
[100%] - Ability to Add to startup through HKCU, HKLM, or ActiveX.
[100%] - Ability to Install Server to preset folders, or define your own location.
[100%] - Built-In Icon Changer.
[100%] - Mutual Exclusion (Mutex)
[100%] - Assembly Information Randomization.
[100%] - Ability to send/receive logs through SMTP w/ fully customizable options.
[100%] - Built-in 1-click Vaccine.exe to remove the virus.
[100%] - Send Screenshots w/ each log.
[100%] - Log Clipboard (Copy Paste).
[100%] - Compile server as .exe/.com/.pif/.scr file.
[100%] - Built-in Multi-File Binder.
In-Progress:
[90%] - Find a better way to obfuscate CodeDOM compiled code. (Going to use memory injection, just need to implement!)
[65%] - Add Ability to hide from task manager (process)
To-Do:
[color=#FF0000][0%] - Add Spreaders.
[0%] - Add Pure Code Stealer. (FF, IE, Chrome, and MSN to start)
[0%] - Ability to specify custom fake error message on first run.
[0%] - Add Melt File
[0%]
- These are just the short-term things I want to add, feel free to post
any ideas/suggestions you have; remember I will already be adding every
feature The Bypass had.
Report date: 2010-11-28 17:04:13 (GMT 1)
File name: polymorphic-keylogger-exe
File size: 1170944 bytes
MD5 hash: 00cfb458de6ed64d3cfccffcf3050484
SHA1 hash: 27cea4cc9f74dfe4787cbc8158773f5c37cd0fb2
Detection rate: 0 on 16 (0%)
Status: CLEAN
Antivirus Database Engine Result
a-squared 28/11/2010 5.0.0.20
Avast 28/11/2010 5.0
AVG 28/11/2010 9.0.0.725
Avira AntiVir 28/11/2010 7.6.0.59
BitDefender 28/11/2010 7.0.0.2555
ClamAV 28/11/2010 0.96.2.1
Comodo 28/11/2010 4.0
Dr.Web 28/11/2010 5.00.0
F-PROT6 28/11/2010 4.6.1.107
Ikarus T3 28/11/2010 1001084
Kaspersky 28/11/2010 9.0.0.736
NOD32 28/11/2010 4.2.42.0
Panda 28/11/2010 10.0.3.0
TrendMicro 28/11/2010 9.120-1004
VBA32 28/11/2010 3.12.14.1
VirusBuster 28/11/2010 1.5.6
Extra information
File type: Executable File (EXE)
Packer: Nothing found
Binder detector: Nothing found
PDF analyzer: Nothing found
FILESERVE
[Tienes que estar registrado y conectado para ver este vínculo]
PASS (Normal Text -> Tripo-5 -> Base64):
YUVCNVk2YTBSemFPL2M3QmRFNVBWNDk2WHphTVZFOXQvemEyV3dUVA==
Comentar es Agradecer, Esta Limpio!,Comprobado
[100%] - Unique Polymorphic Server on every Compile.
[100%] - Ability to Add to startup through HKCU, HKLM, or ActiveX.
[100%] - Ability to Install Server to preset folders, or define your own location.
[100%] - Built-In Icon Changer.
[100%] - Mutual Exclusion (Mutex)
[100%] - Assembly Information Randomization.
[100%] - Ability to send/receive logs through SMTP w/ fully customizable options.
[100%] - Built-in 1-click Vaccine.exe to remove the virus.
[100%] - Send Screenshots w/ each log.
[100%] - Log Clipboard (Copy Paste).
[100%] - Compile server as .exe/.com/.pif/.scr file.
[100%] - Built-in Multi-File Binder.
In-Progress:
[90%] - Find a better way to obfuscate CodeDOM compiled code. (Going to use memory injection, just need to implement!)
[65%] - Add Ability to hide from task manager (process)
To-Do:
[color=#FF0000][0%] - Add Spreaders.
[0%] - Add Pure Code Stealer. (FF, IE, Chrome, and MSN to start)
[0%] - Ability to specify custom fake error message on first run.
[0%] - Add Melt File
[0%]
- These are just the short-term things I want to add, feel free to post
any ideas/suggestions you have; remember I will already be adding every
feature The Bypass had.
Lo he analizado y probado yo mismo, en novirusthanks no se ha detectado nada extraño, también lo he testeado y funciona de pm.
Report date: 2010-11-28 17:04:13 (GMT 1)
File name: polymorphic-keylogger-exe
File size: 1170944 bytes
MD5 hash: 00cfb458de6ed64d3cfccffcf3050484
SHA1 hash: 27cea4cc9f74dfe4787cbc8158773f5c37cd0fb2
Detection rate: 0 on 16 (0%)
Status: CLEAN
Antivirus Database Engine Result
a-squared 28/11/2010 5.0.0.20
Avast 28/11/2010 5.0
AVG 28/11/2010 9.0.0.725
Avira AntiVir 28/11/2010 7.6.0.59
BitDefender 28/11/2010 7.0.0.2555
ClamAV 28/11/2010 0.96.2.1
Comodo 28/11/2010 4.0
Dr.Web 28/11/2010 5.00.0
F-PROT6 28/11/2010 4.6.1.107
Ikarus T3 28/11/2010 1001084
Kaspersky 28/11/2010 9.0.0.736
NOD32 28/11/2010 4.2.42.0
Panda 28/11/2010 10.0.3.0
TrendMicro 28/11/2010 9.120-1004
VBA32 28/11/2010 3.12.14.1
VirusBuster 28/11/2010 1.5.6
Extra information
File type: Executable File (EXE)
Packer: Nothing found
Binder detector: Nothing found
PDF analyzer: Nothing found
FILESERVE
[Tienes que estar registrado y conectado para ver este vínculo]
PASS (Normal Text -> Tripo-5 -> Base64):
YUVCNVk2YTBSemFPL2M3QmRFNVBWNDk2WHphTVZFOXQvemEyV3dUVA==
Comentar es Agradecer, Esta Limpio!,Comprobado