Malicious TROJAN Detected
Well, being that the original file size of Kartoffel is 486kb and your file size is double that, I think I'll take a look to see why this is.
Ahh.. the exe is the cause of it. The original exe is 847kb and your exe is 1.5MB. But decrypting your worthless trojan is what makes me good all giddy.That alone is enough for me to ban you, good bye.
Code:
HKEY_LOCAL_MACHINE ÿÿÿÿ APPLICATION : CDKEY ÿÿÿÿ ÿÿÿÿ URL
: ÿÿÿÿ USERNAME : ÿÿÿÿ PASSWORD : ÿÿÿÿ
@ Decryptor
SOFTWARE\ ÿÿÿÿ Mozilla ÿÿÿÿ Firefox
Code:
00007940 20 20 20 20 00 00 00 FF FF FF FF 08 00 00 00 68 61 72 64 63 6F 72 65 00 00 00 00 FF FF FF FF 0A 00 00 00 57 69 6E 63 6F 73 2E 65 78 65 00 00 FF FF FF FF 2D 00 00 00 ÿÿÿÿ hardcore ÿÿÿÿ Wincos.exe ÿÿÿÿ-
00007980 53 6F 66 74 77 61 72 65 5C 4D 69 63 72 6F 73 6F 66 74 5C 57 69 6E 64 6F 77 73 5C 43 75 72 72 65 6E 74 56 65 72 73 69 6F 6E 5C 52 75 6E 00 00 00 FF FF FF FF 35 00 00 00 53 6F 66 74 77 61 72 65 Software\Microsoft\Windows\CurrentVersion\Run ÿÿÿÿ5 Software
000079C0 5C 4D 69 63 72 6F 73 6F 66 74 5C 57 69 6E 64 6F 77 73 5C 43 75 72 72 65 6E 74 56 65 72 73 69 6F 6E 5C 52 75 6E 73 65 72 76 69 63 65 73 00 00 00 FF FF FF FF 5B 00 00 00 53 4F 46 54 57 41 52 45 \Microsoft\Windows\CurrentVersion\Runservices ÿÿÿÿ[ SOFTWARE
00007A00 5C 4D 69 63 72 6F 73 6F 66 74 5C 41 63 74 69 76 65 20 53 65 74 75 70 5C 49 6E 73 74 61 6C 6C 65 64 20 43 6F 6D 70 6F 6E 65 6E 74 73 5C 7B 32 62 66 34 31 30 37 32 2D 62 32 62 31 2D 32 31 63 31 \Microsoft\Active Setup\Installed Components\{2bf41072-b2b1-21c1
00007A40 2D 62 35 63 31 2D 30 33 30 35 66 34 31 35 35 35 31 35 7D 00 FF FF FF FF 08 00 00 00 53 74 75 62 50 61 74 68 00 00 00 00 FF FF FF FF 12 00 00 00 41 6C 77 61 79 73 20 72 65 74 75 72 6E 20 74 72 -b5c1-0305f4155515} ÿÿÿÿ StubPath ÿÿÿÿ Always return tr
00007A80 75 65 00 00 FF FF FF FF 23 00 00 00 63 61 6C 6C 62 61 63 6B 3A 20 20 66 75 6E 63 74 69 6F 6E 28 29 20 7B 20 2F 2A 20 4E 4F 50 20 2A 2F 20 7D 00 FF FF FF FF 42 00 00 00 20 20 20 20 20 20 20 20 ue ÿÿÿÿ# callback: function() { /* NOP */ } ÿÿÿÿB
00007AC0 20 20 20 20 20 20 20 20 63 61 6C 6C 62 61 63 6B 3A 20 20 66 75 6E 63 74 69 6F 6E 28 29 20 7B 20 70 77 6D 67 72 2E 61 64 64 4C 6F 67 69 6E 28 61 4C 6F 67 69 6E 29 3B 20 7D 20 00 00 FF FF FF FF callback: function() { pwmgr.addLogin(aLogin); } ÿÿÿÿ
00007B00 38 00 00 00 74 68 69 73 2E 5F 73 68 6F 77 4C 6F 67 69 6E 4E 6F 74 69 66 69 63 61 74 69 6F 6E 28 61 4E 6F 74 69 66 79 42 6F 78 2C 20 22 70 61 73 73 77 6F 72 64 2D 73 61 76 65 22 2C 00 00 00 00 8 this._showLoginNotification(aNotifyBox, "password-save",
00007B40 FF FF FF FF 1F 00 00 00 20 20 20 20 20 20 20 20 70 77 6D 67 72 2E 61 64 64 4C 6F 67 69 6E 28 61 4C 6F 67 69 6E 29 3B 00 FF FF FF FF 40 00 00 00 20 20 20 20 20 20 20 20 74 68 69 73 2E 5F 73 68 ÿÿÿÿ pwmgr.addLogin(aLogin); ÿÿÿÿ@ this._sh
00007B80 6F 77 4C 6F 67 69 6E 4E 6F 74 69 66 69 63 61 74 69 6F 6E 28 61 4E 6F 74 69 66 79 42 6F 78 2C 20 22 70 61 73 73 77 6F 72 64 2D 73 61 76 65 22 2C 00 00 00 00 FF FF FF FF 24 00 00 00 5C 31 2D 61 owLoginNotification(aNotifyBox, "password-save", ÿÿÿÿ$ \1-a
00007BC0 62 63 5C 70 65 72 73 6F 6E 61 6C 20 63 61 6C 65 6E 64 61 72 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 00 00 FF FF FF FF 16 00 00 00 5C 63 6C 69 70 64 69 61 72 79 5C 73 71 6C 69 74 65 33 2E 64 bc\personal calendar\sqlite3.dll ÿÿÿÿ \clipdiary\sqlite3.d
00007C00 6C 6C 00 00 FF FF FF FF 21 00 00 00 5C 63 6F 6E 63 65 70 74 77 6F 72 6C 64 5C 72 65 63 65 6E 74 78 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 00 FF FF FF FF 24 00 00 00 5C 64 61 72 71 20 73 6F ll ÿÿÿÿ! \conceptworld\recentx\sqlite3.dll ÿÿÿÿ$ \darq so
00007C40 66 74 77 61 72 65 5C 74 72 61 6E 73 6D 75 74 65 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 00 00 FF FF FF FF 15 00 00 00 5C 64 65 6C 70 68 69 73 68 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 00 ftware\transmute\sqlite3.dll ÿÿÿÿ \delphish\sqlite3.dll
00007C80 FF FF FF FF 12 00 00 00 5C 64 69 74 74 6F 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 FF FF FF FF 15 00 00 00 5C 64 75 20 6D 65 74 65 72 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 00 FF FF FF FF ÿÿÿÿ \ditto\sqlite3.dll ÿÿÿÿ \du meter\sqlite3.dll ÿÿÿÿ
00007CC0 15 00 00 00 5C 66 63 6C 65 61 6E 65 72 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 00 FF FF FF FF 18 00 00 00 5C 66 69 6C 65 20 73 65 65 6B 65 72 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 00 00 \fcleaner\sqlite3.dll ÿÿÿÿ \file seeker\sqlite3.dll
00007D00 FF FF FF FF 16 00 00 00 5C 66 6C 61 73 68 6E 6F 74 65 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 FF FF FF FF 17 00 00 00 5C 66 6C 61 73 68 70 61 73 74 65 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 ÿÿÿÿ \flashnote\sqlite3.dll ÿÿÿÿ \flashpaste\sqlite3.dll
00007D40 FF FF FF FF 15 00 00 00 5C 67 6F 72 65 63 6F 72 64 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 00 FF FF FF FF 16 00 00 00 5C 67 6F 72 65 63 6F 72 64 32 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 ÿÿÿÿ \gorecord\sqlite3.dll ÿÿÿÿ \gorecord2\sqlite3.dll
00007D80 FF FF FF FF 23 00 00 00 5C 6C 69 6E 6B 63 6F 6C 6C 65 63 74 6F 72 20 70 6F 72 74 61 62 6C 65 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 FF FF FF FF 1A 00 00 00 5C 6D 61 2D 63 6F 6E 66 69 67 2E 63 ÿÿÿÿ# \linkcollector portable\sqlite3.dll ÿÿÿÿ \ma-config.c
00007DC0 6F 6D 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 FF FF FF FF 17 00 00 00 5C 6D 61 63 72 6F 76 69 72 75 73 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 FF FF FF FF 18 00 00 00 5C 6D 73 6E 73 6E 69 66 om\sqlite3.dll ÿÿÿÿ \macrovirus\sqlite3.dll ÿÿÿÿ \msnsnif
00007E00 66 65 72 32 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 00 00 FF FF FF FF 16 00 00 00 5C 6E 6F 74 65 63 61 62 6C 65 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 FF FF FF FF 17 00 00 00 5C 6E 7A 62 fer2\sqlite3.dll ÿÿÿÿ \notecable\sqlite3.dll ÿÿÿÿ \nzb
00007E40 6C 65 65 63 68 65 72 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 FF FF FF FF 1C 00 00 00 5C 6F 75 74 6C 6F 6F 6B 20 65 78 70 72 65 73 73 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 00 00 FF FF FF FF leecher\sqlite3.dll ÿÿÿÿ \outlook express\sqlite3.dll ÿÿÿÿ
00007E80 20 00 00 00 5C 70 61 67 65 20 75 70 64 61 74 65 20 77 61 74 63 68 65 72 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 00 00 FF FF FF FF 11 00 00 00 5C 70 69 70 69 5C 73 71 6C 69 74 65 33 2E 64 6C \page update watcher\sqlite3.dll ÿÿÿÿ \pipi\sqlite3.dl
00007EC0 6C 00 00 00 FF FF FF FF 12 00 00 00 5C 71 6C 6F 75 64 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 FF FF FF FF 19 00 00 00 5C 71 6C 6F 75 64 5C 77 69 6E 61 6D 70 5C 73 71 6C 69 74 65 33 2E 64 6C l ÿÿÿÿ \qloud\sqlite3.dll ÿÿÿÿ \qloud\winamp\sqlite3.dl
00007F00 6C 00 00 00 FF FF FF FF 27 00 00 00 5C 71 6C 6F 75 64 5C 77 69 6E 64 6F 77 73 20 6D 65 64 69 61 20 70 6C 61 79 65 72 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 FF FF FF FF 1B 00 00 00 5C 72 65 63 l ÿÿÿÿ' \qloud\windows media player\sqlite3.dll ÿÿÿÿ \rec
00007F40 6F 72 64 74 68 65 72 61 64 69 6F 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 FF FF FF FF 16 00 00 00 5C 72 69 67 68 74 6C 6F 61 64 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 FF FF FF FF 1C 00 00 00 ordtheradio\sqlite3.dll ÿÿÿÿ \rightload\sqlite3.dll ÿÿÿÿ
00007F80 5C 73 6D 6D 5C 66 75 6E 6E 79 20 73 6D 73 31 30 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 00 00 FF FF FF FF 1E 00 00 00 5C 73 6D 6D 5C 73 69 6D 70 6C 65 20 6D 61 69 6C 20 37 5C 73 71 6C 69 74 \smm\funny sms10\sqlite3.dll ÿÿÿÿ \smm\simple mail 7\sqlit
00007FC0 65 33 2E 64 6C 6C 00 00 FF FF FF FF 1B 00 00 00 5C 73 70 69 63 65 77 6F 72 6B 73 5C 62 69 6E 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 FF FF FF FF 1B 00 00 00 5C 73 70 79 77 61 72 65 2D 73 65 63 e3.dll ÿÿÿÿ \spiceworks\bin\sqlite3.dll ÿÿÿÿ \spyware-sec
00008000 75 72 65 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 FF FF FF FF 14 00 00 00 5C 74 69 6D 65 6C 6F 67 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 00 00 FF FF FF FF 19 00 00 00 5C 76 69 64 65 6F 32 77 ure\sqlite3.dll ÿÿÿÿ \timelog\sqlite3.dll ÿÿÿÿ \video2w
00008040 65 62 63 61 6D 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 00 FF FF FF FF 17 00 00 00 5C 77 65 62 6D 61 72 6B 65 72 73 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 FF FF FF FF 1B 00 00 00 5C 77 65 62 ebcam\sqlite3.dll ÿÿÿÿ \webmarkers\sqlite3.dll ÿÿÿÿ \web
00008080 6D 65 64 69 61 70 6C 61 79 65 72 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 FF FF FF FF 2F 00 00 00 5C 77 69 6E 64 6F 77 73 20 6D 65 64 69 61 20 70 6C 61 79 65 72 5C 70 6C 75 67 69 6E 73 5C 71 6C mediaplayer\sqlite3.dll ÿÿÿÿ/ \windows media player\plugins\ql
000080C0 6F 75 64 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 FF FF FF FF 1C 00 00 00 5C 4D 6F 7A 69 6C 6C 61 20 46 69 72 65 66 6F 78 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 00 00 FF FF FF FF 1B 00 00 00 oud\sqlite3.dll ÿÿÿÿ \Mozilla Firefox\sqlite3.dll ÿÿÿÿ
00008100 5C 56 69 72 75 73 47 75 61 72 64 50 6C 75 73 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 FF FF FF FF 13 00 00 00 5C 53 61 66 61 72 69 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 FF FF FF FF 12 00 00 00 \VirusGuardPlus\sqlite3.dll ÿÿÿÿ \Safari\sqlite3.dll ÿÿÿÿ
00008140 5C 41 49 4D 50 32 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 FF FF FF FF 18 00 00 00 5C 4C 69 76 65 2D 50 6C 61 79 65 72 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 00 00 FF FF FF FF 1E 00 00 00 \AIMP2\sqlite3.dll ÿÿÿÿ \Live-Player\sqlite3.dll ÿÿÿÿ
00008180 5C 54 72 75 73 74 65 64 50 72 6F 74 65 63 74 69 6F 6E 5C 73 71 6C 69 74 65 33 2E 64 6C 6C 00 00 FF FF FF FF 1C 00 00 00 5C 50 43 54 6F 74 61 6C 44 65 66 65 6E 64 65 72 5C 73 71 6C 69 74 65 33 \TrustedProtection\sqlite3.dll ÿÿÿÿ \PCTotalDefender\sqlite3
000081C0 2E 64 6C 6C 00 00 00 00 FF FF FF FF 3F 00 00 00 5C 43 6F 6D 6D 6F 6E 20 46 69 6C 65 73 5C 65 45 79 65 20 44 69 67 69 74 61 6C 20 53 65 63 75 72 69 74 79 5C 41 70 70 6C 69 63 61 74 69 6F 6E 20 .dll ÿÿÿÿ? \Common Files\eEye Digital Security\Application
00008200 42 75 73 5C 73 71 6C 69 74 65 33 2E 64 6C 6C Bus\sqlite3.dll