Les dejo esta mod de un Crypt de DuNeD@i del año 2010
Me ha costado muchisimo hacerla, ya que todas las firmas eran muy dificles



Imagen



Testado con la tool del compañero cruZ

Imagen



Reportes Antes


Date and Time: 11/18/2014 22:58:16 UTC\n

File Name: ServerCyberAntes.exe
File Size: 306.57 KB
MD5: 7a81b6836e1dacc9ee09b674147fd7e3
SHA1: 26b3ff6e5b80ca54d61fea5a8d49fa0b0d69a6c0
Detection: 26 of 35 (74%)
Status: INFECTED

AVG Free - Trojan horse VBCrypt.DRW
Avast - Win32:VBCrypt-AZQ [Trj]
AntiVir (Avira) - TR/Dropper.Gen
BitDefender - Gen:Trojan.Heur.VP.tm3@ae7vCpP
Clam Antivirus - Clean!
COMODO Internet Security - Worm.Win32.VBNA.~gen@105156883
Dr.Web - Trojan.MulDrop3.47226
eTrust-Vet - Win32/VBInject.M!generic
F-PROT Antivirus - W32/VBTrojan.9!Maximus
F-Secure Internet Security - Gen:Variant.Symmi.2407
G Data - Gen:Variant.Symmi.2407, Win32:Inject-AQR [Trj]
IKARUS Security - Worm.Win32.Dorkbot
Kaspersky Antivirus - Backdoor.Win32.LolBot.tp
McAfee - Clean!
MS Security Essentials - VirTool:Win32/VBInject.DW
ESET NOD32 - Trojan.Win32/Injector.CDI
Norman - Gen:Variant.Symmi.2407
Norton Antivirus - Clean!
Panda Security - Suspicious
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Troj/VB-FDO
Trend Micro Internet Security - Clean!
VBA32 Antivirus - infected SScope.Malware-Cryptor.VBCR.1841
Zoner AntiVirus - Clean!
Ad-Aware - Gen:Variant.Symmi.2407
BullGuard - Gen:Variant.Graftor.1129
FortiClient - W32/Refroso.BLC!tr
K7 Ultimate - Backdoor ( 0023d3101 )
NANO Antivirus - Trojan.Win32.LolBot.cnwspn
Panda CommandLine - Trj/Genetic.gen
SUPERAntiSpyware - Clean!
Twister Antivirus - Suspicious:Suspicious.86CB@[email protected]
VIPRE - VirTool.Win32.VBInject.b (v)

[Enlace externo eliminado para invitados]


Date and Time: 11/18/2014 23:01:23 UTC\n

File Name: SpyNetAntes.exe
File Size: 504.57 KB
MD5: 4a553f5e12f456df8b5d91fa2e8958fa
SHA1: 172df568b1990642acc41774a81a4e0037101a8b
Detection: 27 of 35 (77%)
Status: INFECTED

AVG Free - Trojan horse VBCrypt.DRW
Avast - Win32:VBCrypt-AZQ [Trj]
AntiVir (Avira) - TR/Dropper.Gen
BitDefender - Gen:Trojan.Heur.VP.Fm3@ae7vCpP
Clam Antivirus - Clean!
COMODO Internet Security - Worm.Win32.VBNA.~gen@105156883
Dr.Web - Trojan.MulDrop3.47226
eTrust-Vet - Win32/VBInject.M!generic
F-PROT Antivirus - W32/VBTrojan.9!Maximus
F-Secure Internet Security - Gen:Variant.Symmi.2119
G Data - Gen:Variant.Symmi.2119, Win32:Inject-AQR [Trj]
IKARUS Security - Worm.Win32.Dorkbot
Kaspersky Antivirus - Backdoor.Win32.LolBot.tp
McAfee - Clean!
MS Security Essentials - VirTool:Win32/VBInject.gen!DG
ESET NOD32 - Trojan.Win32/Injector.CDI
Norman - Gen:Variant.Symmi.2119
Norton Antivirus - Trojan.Usuge!gen3
Panda Security - Suspicious
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Troj/VB-FDO
Trend Micro Internet Security - Clean!
VBA32 Antivirus - infected SScope.Malware-Cryptor.VBCR.1841
Zoner AntiVirus - Clean!
Ad-Aware - Gen:Variant.Symmi.2119
BullGuard - Gen:Variant.Graftor.1129
FortiClient - W32/Refroso.BLC!tr
K7 Ultimate - Backdoor ( 0023d3101 )
NANO Antivirus - Trojan.Win32.LolBot.cnwspn
Panda CommandLine - Trj/Genetic.gen
SUPERAntiSpyware - Clean!
Twister Antivirus - Suspicious:Suspicious.86CB@[email protected]
VIPRE - VirTool.Win32.VBInject.b (v)

[Enlace externo eliminado para invitados]


Date and Time: 11/18/2014 23:02:58 UTC\n

File Name: DarkCometAntes.exe
File Size: 287.57 KB
MD5: 8fae9bdc9c82ef999d6c8fd96e50e0f7
SHA1: b16942966c929c3d5d7d62f3cbb7618128c5c80a
Detection: 26 of 35 (74%)
Status: INFECTED

AVG Free - Trojan horse VBCrypt.DRW
Avast - Win32:VBCrypt-AZQ [Trj]
AntiVir (Avira) - TR/Dropper.Gen
BitDefender - Gen:Variant.Symmi.2407
Clam Antivirus - Clean!
COMODO Internet Security - Worm.Win32.VBNA.~gen@105156883
Dr.Web - Trojan.MulDrop3.47226
eTrust-Vet - Win32/VBInject.M!generic
F-PROT Antivirus - W32/VBTrojan.9!Maximus
F-Secure Internet Security - Gen:Variant.Symmi.2407
G Data - Gen:Variant.Symmi.2407, Win32:Inject-AQR [Trj]
IKARUS Security - Worm.Win32.Dorkbot
Kaspersky Antivirus - Backdoor.Win32.LolBot.tp
McAfee - Clean!
MS Security Essentials - VirTool:Win32/VBInject.DW
ESET NOD32 - Trojan.Win32/Injector.CDI
Norman - Clean!
Norton Antivirus - Trojan.Usuge!gen3
Panda Security - Suspicious
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Troj/VB-FDO
Trend Micro Internet Security - Clean!
VBA32 Antivirus - infected SScope.Malware-Cryptor.VBCR.1841
Zoner AntiVirus - Clean!
Ad-Aware - Gen:Variant.Symmi.2407
BullGuard - Gen:Variant.Graftor.1129
FortiClient - W32/Refroso.BLC!tr
K7 Ultimate - Backdoor ( 0023d3101 )
NANO Antivirus - Trojan.Win32.LolBot.cnwspn
Panda CommandLine - Trj/Genetic.gen
SUPERAntiSpyware - Clean!
Twister Antivirus - Suspicious:Suspicious.86CB@[email protected]
VIPRE - VirTool.Win32.VBInject.b (v)

[Enlace externo eliminado para invitados]


Date and Time: 11/18/2014 23:04:17 UTC\n

File Name: XtremeAntes.exe
File Size: 57.07 KB
MD5: 8a9b5d8aea2eb4942d1bc2981a891079
SHA1: fb14adead65a741b4f0d7cf3fa12f41869e56afa
Detection: 27 of 35 (77%)
Status: INFECTED

AVG Free - Trojan horse VBCrypt.DRW
Avast - Win32:VBCrypt-AZQ [Trj]
AntiVir (Avira) - TR/Dropper.Gen
BitDefender - Gen:Variant.Symmi.31905
Clam Antivirus - Clean!
COMODO Internet Security - Worm.Win32.VBNA.~gen@105156883
Dr.Web - Trojan.MulDrop3.47226
eTrust-Vet - Win32/VBInject.M!generic
F-PROT Antivirus - W32/VBTrojan.9!Maximus
F-Secure Internet Security - Gen:Variant.Symmi.31905
G Data - Gen:Variant.Symmi.31905
IKARUS Security - Worm.Win32.Dorkbot
Kaspersky Antivirus - Backdoor.Win32.LolBot.tp
McAfee - Clean!
MS Security Essentials - VirTool:Win32/VBInject.DW
ESET NOD32 - Trojan.Win32/Injector.CDI
Norman - Clean!
Norton Antivirus - Trojan.Usuge!gen3
Panda Security - Suspicious
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Troj/VB-FDO
Trend Micro Internet Security - Clean!
VBA32 Antivirus - infected SScope.Malware-Cryptor.VBCR.1841
Zoner AntiVirus - Clean!
Ad-Aware - Gen:Variant.Symmi.31905
BullGuard - Gen:Variant.Graftor.1129
FortiClient - W32/Refroso.BLC!tr
K7 Ultimate - Backdoor ( 0023d3101 )
NANO Antivirus - Trojan.Win32.LolBot.cnwspn
Panda CommandLine - Trj/Genetic.gen
SUPERAntiSpyware - Trojan.Agent/Gen-Falcomp[Cont].Process
Twister Antivirus - Suspicious:Suspicious.86CB@[email protected]
VIPRE - VirTool.Win32.VBInject.b (v)

[Enlace externo eliminado para invitados]


Reportes despues

Date and Time: 11/18/2014 23:06:12 UTC\n

File Name: DarkComet.EXE
File Size: 287.57 KB
SHA1: 2e3116b10bf2f7e9f96baadb6610c989cf944a1b
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

[Enlace externo eliminado para invitados]


Date and Time: 11/18/2014 23:08:36 UTC\n

File Name: ServerCyber.exe
File Size: 306.57 KB
SHA1: ac266df7d6cac1b5de33eabb17a0b67f35d6723b
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

[Enlace externo eliminado para invitados]


Date and Time: 11/18/2014 23:11:32 UTC\n

File Name: SpyNet.exe
File Size: 504.57 KB
SHA1: 80f2c232e41df12687826d19b46fa679c78a90a0
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

[Enlace externo eliminado para invitados]


Date and Time: 11/18/2014 23:13:48 UTC\n

File Name: XtremeRat.exe
File Size: 57.07 KB
SHA1: a812985bbb08e76fe7e9b79d63af849ea617fbef
Detection: 0 of 35 (0%)
Status: CLEAN

AVG Free - Clean!
Avast - Clean!
AntiVir (Avira) - Clean!
BitDefender - Clean!
Clam Antivirus - Clean!
COMODO Internet Security - Clean!
Dr.Web - Clean!
eTrust-Vet - Clean!
F-PROT Antivirus - Clean!
F-Secure Internet Security - Clean!
G Data - Clean!
IKARUS Security - Clean!
Kaspersky Antivirus - Clean!
McAfee - Clean!
MS Security Essentials - Clean!
ESET NOD32 - Clean!
Norman - Clean!
Norton Antivirus - Clean!
Panda Security - Clean!
A-Squared - Clean!
Quick Heal Antivirus - Clean!
Solo Antivirus - Clean!
Sophos - Clean!
Trend Micro Internet Security - Clean!
VBA32 Antivirus - Clean!
Zoner AntiVirus - Clean!
Ad-Aware - Clean!
BullGuard - Clean!
FortiClient - Clean!
K7 Ultimate - Clean!
NANO Antivirus - Clean!
Panda CommandLine - Clean!
SUPERAntiSpyware - Clean!
Twister Antivirus - Clean!
VIPRE - Clean!

[Enlace externo eliminado para invitados]


Descarga
[spoiler][Enlace externo eliminado para invitados][/spoiler]
Pass
[spoiler]MODByRoda[/spoiler]


Agradecimiento y Creditos

MCN per condividere la loro conoscenza quotidiana
Metal_Kingdom por su gentileza y buena onda de estar siempre predispuesto para ayudar!

Sin mas

Saludos
Contacto Skype: Rodrilanus
O.o excelente limpieza, grande, va perfect
Somos dueños de nuestro silencio y exclavos de nuestras palabras
Admito donaciones por mis aportes por bitcoin : 1FK5cdrzPZB19BYaiVkasWzJJnhG8Ss6An
La torpeza de algunas compañias me hace reir....
Responder

Volver a “Troyanos y Herramientas”