Jump to content
YOUR-AD-HERE
HOSTING
TOOLS
992Proxy

Locked HMA Ultimate Proxy Grabber v1.1


135

Recommended Posts

  • 5 months later...

Re: HMA Ultimate Proxy Grabber v1.1

 

Checked for debuggers

Code injection in process: c:\windows\system32\werfault.exe

Created a mutex named: Global\f87e12ca-5a85-11e2-918a-000c297913dd

Created a mutex named: Local\!IETld!Mutex

Created a mutex named: Local\WERReportingForProcess203524

Created an event named: Global\RestartMSIDLLv327680.498089985

Created an event named: Global\ShutdownMSIDLLv327680.498089985

Created an event named: OleDfRootD132CE98528FCCF3

Created process: C:\Windows\system32\WerFault.exe,C:\Windows\system32\WerFault.exe -u -p 203524 -s 820,C:\Windows\system32

Defined Log_API entry: Traces of Max++

Detected process privilege elevation

Enumerated running processes

Got system default language ID

Got user name information

 

 

 

a backdoor program which you share here, admins please check this tool and verify ... stealing all information from computer when run it

Link to comment
Share on other sites

Re: HMA Ultimate Proxy Grabber v1.1

 

Checked for debuggers

Code injection in process: c:\windows\system32\werfault.exe

Created a mutex named: Global\f87e12ca-5a85-11e2-918a-000c297913dd

Created a mutex named: Local\!IETld!Mutex

Created a mutex named: Local\WERReportingForProcess203524

Created an event named: Global\RestartMSIDLLv327680.498089985

Created an event named: Global\ShutdownMSIDLLv327680.498089985

Created an event named: OleDfRootD132CE98528FCCF3

Created process: C:\Windows\system32\WerFault.exe,C:\Windows\system32\WerFault.exe -u -p 203524 -s 820,C:\Windows\system32

Defined Log_API entry: Traces of Max++

Detected process privilege elevation

Enumerated running processes

Got system default language ID

Got user name information

 

 

 

a backdoor program which you share here, admins please check this tool and verify ... stealing all information from computer when run it

 

 

 

Go to Mikisoft´s blog and say him that this tool is backdoored lol.....

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.