Sabtu, 11 Desember 2010

Rheo@sukatoro

Rheo@sukatoro
----------------------
Hack
----------------------
F2=Rank
F3=Title
F4=Spion
----------------------
MapHack
----------------------
Numpad1=Library
Numpad2=BurningHall
Numpad3=Luxville
Numpad4=Mstation
Numpad5=Training Camp
Numpad6=Downtown
Numpad7=Mini Indonesia
Numpad8=CrackDown
Numpad9=Midtown
Numpad0=KickPoint
F1=EsternRoad
----------------------
Masmed
----------------------
Insert=on
Delete=off
----------------------
Room
----------------------
Free=F11 (Beta)
AWP =F12
----------------------
Minimize
----------------------
F9 =on
F10=off
----------------------

Credit by me Rheo@sukatoro (Zimaxhacker.blogspot.com)


scan virus :[left][left]


0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name:
rheon3.exe
Submission date:
2010-12-11 12:34:23 (UTC)
Current status:
queued queued analysing finished
Result:
2/ 43 (4.7%)

VT Community

not reviewed
Safety score: -
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 2010.12.11.00 2010.12.10 -
AntiVir 7.10.14.255 2010.12.10 -
Antiy-AVL 2.0.3.7 2010.12.11 -
Avast 4.8.1351.0 2010.12.10 -
Avast5 5.0.677.0 2010.12.10 -
AVG 9.0.0.851 2010.12.11 -
BitDefender 7.2 2010.12.11 -
CAT-QuickHeal 11.00 2010.12.11 -
ClamAV 0.96.4.0 2010.12.11 -
Command 5.2.11.5 2010.12.11 -
Comodo 7021 2010.12.11 -
DrWeb 5.0.2.03300 2010.12.11 -
Emsisoft 5.1.0.1 2010.12.11 -
eSafe 7.0.17.0 2010.12.09 -
eTrust-Vet 36.1.8034 2010.12.10 -
F-Prot 4.6.2.117 2010.12.11 -
F-Secure 9.0.16160.0 2010.12.11 -
Fortinet 4.2.254.0 2010.12.11 -
GData 21 2010.12.11 -
Ikarus T3.1.1.90.0 2010.12.11 -
Jiangmin 13.0.900 2010.12.11 -
K7AntiVirus 9.71.3211 2010.12.10 -
Kaspersky 7.0.0.125 2010.12.11 -
McAfee 5.400.0.1158 2010.12.11 -
McAfee-GW-Edition 2010.1C 2010.12.11 -
Microsoft 1.6402 2010.12.11 -
NOD32 5693 2010.12.10 -
Norman 6.06.12 2010.12.11 -
nProtect 2010-12-10.01 2010.12.10 -
Panda 10.0.2.7 2010.12.11 Suspicious file
PCTools 7.0.3.5 2010.12.11 -
Prevx 3.0 2010.12.11 -
Rising 22.77.04.00 2010.12.11 -
Sophos 4.60.0 2010.12.11 Sus/VB-AG
SUPERAntiSpyware 4.40.0.1006 2010.12.11 -
Symantec 20101.3.0.103 2010.12.11 -
TheHacker 6.7.0.1.098 2010.12.11 -
TrendMicro 9.120.0.1004 2010.12.11 -
TrendMicro-HouseCall 9.120.0.1004 2010.12.11 -
VBA32 3.12.14.2 2010.12.10 -
VIPRE 7602 2010.12.11 -
ViRobot 2010.12.11.4196 2010.12.11 -
VirusBuster 13.6.86.0 2010.12.10 -
Additional information
Show all
MD5 : 1352041aa956333ba9c5eb51cb04b181
SHA1 : 41464951c830d676f5be96220683e2f008bb1a74
SHA256: 29979473e01a59dd15e5fc724bf95e62192e01435696eca534738fd854899596
ssdeep: 768:pREfSrVb+gMczo8MJmlBKEfDob8cCsVxVMs8skESTIR79:7EfGVb+gy8MzEFs/d9
File size : 61440 bytes
First seen: 2010-12-11 12:34:23
Last seen : 2010-12-11 12:34:23
TrID:
Win32 Executable Microsoft Visual Basic 6 (86.2%)
Win32 Executable Generic (5.8%)
Win32 Dynamic Link Library (generic) (5.1%)
Generic Win/DOS Executable (1.3%)
DOS Executable Generic (1.3%)
sigcheck:
publisher....: zimaxhacker.blogspot.com
copyright....: n/a
product......: rheo
description..: n/a
original name: rheon3.exe
internal name: rheon3
file version.: 1.00
comments.....: www.zimaxhacker.blogspot.com
signers......: -
signing date.: -
verified.....: Unsigned
PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x1760
timedatestamp....: 0x4D036E34 (Sat Dec 11 12:27:32 2010)
machinetype......: 0x14c (I386)

[[ 3 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0xB7F0, 0xC000, 6.37, bb4b1739cde03256ae1b503af7294155
.data, 0xD000, 0xD9C, 0x1000, 0.00, 620f0b67a91f7f74151bc5be745b7110
.rsrc, 0xE000, 0x93C, 0x1000, 2.02, 5ca438e9a5f94bca7edd022a40d1f66f

[[ 1 import(s) ]]
MSVBVM60.DLL: __vbaVarSub, __vbaI2Sgn, _CIcos, _adj_fptan, __vbaStrI4, __vbaVarMove, __vbaVarVargNofree, __vbaFreeVar, __vbaLenBstr, __vbaFreeVarList, __vbaEnd, _adj_fdiv_m64, __vbaFreeObjList, -, -, _adj_fprem1, __vbaRecAnsiToUni, -, __vbaCopyBytes, __vbaStrCat, __vbaLsetFixstr, __vbaRecDestruct, __vbaSetSystemError, __vbaHresultCheckObj, _adj_fdiv_m32, __vbaAryDestruct, __vbaExitProc, __vbaVarForInit, __vbaOnError, __vbaObjSet, -, _adj_fdiv_m16i, __vbaObjSetAddref, _adj_fdivr_m16i, -, __vbaFpR4, __vbaStrFixstr, __vbaVarTstLt, _CIsin, -, -, -, __vbaChkstk, EVENT_SINK_AddRef, __vbaGenerateBoundsError, __vbaStrCmp, __vbaI2I4, DllFunctionCall, __vbaCastObjVar, __vbaRedimPreserve, _adj_fpatan, __vbaLateIdCallLd, __vbaRedim, __vbaRecUniToAnsi, EVENT_SINK_Release, __vbaUI1I2, _CIsqrt, EVENT_SINK_QueryInterface, __vbaExceptHandler, __vbaStrToUnicode, -, _adj_fprem, _adj_fdivr_m64, __vbaVarDiv, __vbaFPException, __vbaInStrVar, __vbaUbound, __vbaStrVarVal, -, __vbaI2Var, -, -, _CIlog, __vbaErrorOverflow, __vbaR8Str, __vbaInStr, __vbaNew2, _adj_fdiv_m32i, _adj_fdivr_m32i, __vbaStrCopy, __vbaFreeStrList, _adj_fdivr_m32, _adj_fdiv_r, -, __vbaI4Var, __vbaVarAdd, __vbaVarDup, __vbaStrToAnsi, -, __vbaFpI4, __vbaRecDestructAnsi, _CIatan, -, __vbaStrMove, __vbaCastObj, __vbaStrVarCopy, _allmul, __vbaLateIdSt, _CItan, __vbaVarForNext, _CIexp, __vbaMidStmtBstr, __vbaFreeObj, __vbaFreeStr
ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 49152
Comments: www.zimaxhacker.blogspot.com
CompanyName: zimaxhacker.blogspot.com
EntryPoint: 0x1760
FileFlagsMask: 0x0000
FileOS: Win32
FileSize: 60 kB
FileSubtype: 0
FileType: Win32 EXE
FileVersion: 1.0
FileVersionNumber: 1.0.0.0
ImageVersion: 1.0
InitializedDataSize: 8192
InternalName: rheon3
LanguageCode: English (U.S.)
LinkerVersion: 6.0
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 4.0
ObjectFileType: Executable application
OriginalFilename: rheon3.exe
PEType: PE32
ProductName: rheo
ProductVersion: 1.0
ProductVersionNumber: 1.0.0.0
Subsystem: Windows GUI
SubsystemVersion: 4.0
TimeStamp: 2010:12:11 13:27:32+01:00
UninitializedDataSize: 0


maap masih newbie jadi berantakan...

happy cheating...

My Blog : http://zimaxhacker.blogspot.com/



jangan lupa + nya....

thax
SENGGOL AJA YANG INI GAN