
Antes Stub
Report generated: 26.5.2009 at 14.46.29 (GMT 1)
Filename: stub.exe
File size: 24 KB
MD5 Hash: CEF057EDB20CC305014643C11955F151
SHA1 Hash: 971EC9F5DDA58495CF671953A3B17DFC966E913D
Packer detected: Microsoft Visual Basic 5.0 / 6.0
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
Detection rate: 15 on 24
Detections
a-squared - Trojan-PWS.Win32.LdPinch!IK
Avira AntiVir - TR/PSW.LdPinch.afhw
Avast - Win32:VB-LMQ [Drp]
AVG - BackDoor.Generic11.JLB
BitDefender - Trojan.Generic.1630395
ClamAV - Nothing found!
Comodo - TrojWare.Win32.PSW.LdPinch.afhg
Dr.Web - Nothing found!
Ewido - Nothing found!
F-PROT 6 - Nothing found!
G DATA - Nothing found!
IkarusT3 - Trojan-PWS.Win32.LdPinch
Kaspersky - Trojan-PSW.Win32.LdPinch.afhg
McAfee - PWS-LDPinch!a trojan
MHR (Malware Hash Registry) - Virus Found - detect rate 26%
NOD32 v3 - Nothing found!
Norman - Nothing found!
Panda - Trj/Ldpinch.WE
Quick Heal - TrojanPSW.LdPinch.afkw
Solo Antivirus - Nothing found!
Sophos - Mal/UnkPack-Fam
TrendMicro - Nothing found!
VBA32 - Trojan-Dropper.Win32.VB.yab
Virus Buster - Trojan.PWS.LdPinch.YLD
Ahora Stub
Report generated: 26.5.2009 at 14.33.34 (GMT 1)
Filename: stub.exe
File size: 24 KB
MD5 Hash: 5FE7CB73AE2B307B25EDE3E13FB52D25
SHA1 Hash: DC7198612B9C8956668D05D7702425CDC231ACF2
Packer detected: Microsoft Visual Basic 5.0 / 6.0
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
Detection rate: 0 on 24
Detections
a-squared - Nothing found!
Avira AntiVir - Nothing found!
Avast - Nothing found!
AVG - Nothing found!
BitDefender - Nothing found!
ClamAV - Nothing found!
Comodo - Nothing found!
Dr.Web - Nothing found!
Ewido - Nothing found!
F-PROT 6 - Nothing found!
G DATA - Nothing found!
IkarusT3 - Nothing found!
Kaspersky - Nothing found!
McAfee - Nothing found!
MHR (Malware Hash Registry) - Nothing found!
NOD32 v3 - Nothing found!
Norman - Nothing found!
Panda - Nothing found!
Quick Heal - Nothing found!
Solo Antivirus - Nothing found!
Sophos - Nothing found!
TrendMicro - Nothing found!
VBA32 - Nothing found!
Virus Buster - Nothing found!
Con Poison Ivy
Report generated: 26.5.2009 at 14.34.17 (GMT 1)
Filename: CRYPTED.exe
File size: 32 KB
MD5 Hash: F56AF293036C840B9F84177D732675A9
SHA1 Hash: 4E1FBBEB5B356B2A612092EA62E817D8149D32F9
Packer detected: Microsoft Visual Basic 5.0 / 6.0
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
Detection rate: 2 on 24
Detections
a-squared - Trojan-Spy.Drivec!IK
Avira AntiVir - Nothing found!
Avast - Nothing found!
AVG - Nothing found!
BitDefender - Nothing found!
ClamAV - Nothing found!
Comodo - Nothing found!
Dr.Web - Nothing found!
Ewido - Nothing found!
F-PROT 6 - Nothing found!
G DATA - Nothing found!
IkarusT3 - Trojan-Spy.Drivec
Kaspersky - Nothing found!
McAfee - Nothing found!
MHR (Malware Hash Registry) - Nothing found!
NOD32 v3 - Nothing found!
Norman - Nothing found!
Panda - Nothing found!
Quick Heal - Nothing found!
Solo Antivirus - Nothing found!
Sophos - Nothing found!
TrendMicro - Nothing found!
VBA32 - Nothing found!
Virus Buster - Nothing found!
y ahora metemos el server del Poison Ivy encryptado al Hexworshop y nos vamos al offset 32616 y remplazamos por 2E como se aprecia en la imagen.

Y Ahora con Poison ivy
Report generated: 26.5.2009 at 14.41.09 (GMT 1)
Filename: CRYPTED.exe
File size: 32 KB
MD5 Hash: AD3EB7849219C9C027B337280F25BB95
SHA1 Hash: F61475E2B1DE6A4EB3B62C4041FD2109DCD044ED
Packer detected: Microsoft Visual Basic 5.0 / 6.0
Self-Extract Archive: Nothing found
Binder Detector: Nothing found
Detection rate: 0 on 24
Detections
a-squared - Nothing found!
Avira AntiVir - Nothing found!
Avast - Nothing found!
AVG - Nothing found!
BitDefender - Nothing found!
ClamAV - Nothing found!
Comodo - Nothing found!
Dr.Web - Nothing found!
Ewido - Nothing found!
F-PROT 6 - Nothing found!
G DATA - Nothing found!
IkarusT3 - Nothing found!
Kaspersky - Nothing found!
McAfee - Nothing found!
MHR (Malware Hash Registry) - Nothing found!
NOD32 v3 - Nothing found!
Norman - Nothing found!
Panda - Nothing found!
Quick Heal - Nothing found!
Solo Antivirus - Nothing found!
Sophos - Nothing found!
TrendMicro - Nothing found!
VBA32 - Nothing found!
Virus Buster - Nothing found!
[Enlace externo eliminado para invitados]