Pages

Monday, February 23, 2009

eMule 0.49c ZZUL 20090222-2320


eMule v0.49c ZZUL 20090222-2320

merge to 0.49c base
This is SlotFocus + Powershare + some other small stuff that's always been in ZZUL but isn't in official.

Download

ed2k:
eMule_0.49c_ZZUL_20090222-2320.zip

http: eMule_0.49c_ZZUL_20090222-2320.zip 2.35 MB

Emule 0.49C Zzul 20090222-2320 Source.zip

http: http://uploaded.to/file/amx7mh/eMule_0.49c_ZZUL_20090222-2320_source.zip

Direct Links:
eMule_0.49c_ZZUL_20090222-2320.zip
eMule_0.49c_ZZUL_20090222-2320_source.zip

It's a Xtreme powerfull releaser mod! Thanx for quick update!



================================================



Caution by eMule search there shown up some new viruses like this:



inside is a setup.exe in this scheme:

(emuleversion)space programname space .zip or space .rar

(0.49c Beta 1) emule sins .zip

(0.49c Beta 1) emule any modname .zip

the file renames it by self for example to:
(0.49c Beta 1) giochi nintendods .zip
Genuine_Licence....
(0.49c Beta 1) eMule .rar

under Random names in ed2k net!



look only the header before executing such files:


000640 1D 00 00 00 14 16 00 00 14 0A 00 00 43 68 65 63 ............Chec
000650 6B 54 6F 6B 65 6E 4D 65 6D 62 65 72 73 68 69 70 kTokenMembership
000660 00 00 00 00 61 64 76 61 70 69 33 32 2E 64 6C 6C ....advapi32.dll
000670 00 00 00 00 53 65 53 68 75 74 64 6F 77 6E 50 72 ....SeShutdownPr
000680 69 76 69 6C 65 67 65 00 44 65 6C 4E 6F 64 65 52 ivilege.DelNodeR
000690 75 6E 44 4C 4C 33 32 00 61 64 76 70 61 63 6B 2E unDLL32.advpack.
0006A0 64 6C 6C 00 2E 2E 00 00 2E 00 00 00 2A 00 00 00 dll.........*...
0006B0 77 69 6E 69 6E 69 74 2E 69 6E 69 00 25 6C 75 00 wininit.ini.%lu.
0006C0 53 6F 66 74 77 61 72 65 5C 4D 69 63 72 6F 73 6F Software\Microso
0006D0 66 74 5C 57 69 6E 64 6F 77 73 5C 43 75 72 72 65 ft\Windows\Curre
0006E0 6E 74 56 65 72 73 69 6F 6E 5C 41 70 70 20 50 61 ntVersion\App Pa
0006F0 74 68 73 00 2E 42 41 54 00 00 00 00 73 65 74 75 ths..BAT....setu
000700 70 61 70 69 2E 64 6C 6C 00 00 00 00 73 65 74 75 papi.dll....setu
000710 70 78 2E 64 6C 6C 00 00 56 65 72 73 69 6F 6E 00 px.dll..Version.
000720 41 64 76 61 6E 63 65 64 49 4E 46 00 52 65 62 6F AdvancedINF.Rebo
000730 6F 74 00 00 5D 00 00 00 5B 00 00 00 2E 49 4E 46 ot..]...[....INF
000740 00 00 00 00 20 00 00 00 22 00 00 00 5C 00 00 00 .... ..."...\...
000750 55 50 44 46 49 4C 45 25 6C 75 00 00 43 41 42 49 UPDFILE%lu..CABI
000760 4E 45 54 00 49 58 50 00 49 58 50 25 30 33 64 2E NET.IXP.IXP%03d.
000770 54 4D 50 00 52 65 67 53 65 72 76 65 72 00 00 00 TMP.RegServer...
000780 4C 6F 61 64 53 74 72 69 6E 67 28 29 20 45 72 72 LoadString() Err
000790 6F 72 2E 20 20 43 6F 75 6C 64 20 6E 6F 74 20 6C or. Could not l
0007A0 6F 61 64 20 73 74 72 69 6E 67 20 72 65 73 6F 75 oad string resou
0007B0 72 63 65 2E 00 00 00 00 50 41 43 4B 49 4E 53 54 rce.....PACKINST
0007C0 53 50 41 43 45 00 00 00 46 49 4C 45 53 49 5A 45 SPACE...FILESIZE
0007D0 53 00 00 00 3C 4E 6F 6E 65 3E 00 00 55 50 52 4F S.....UPRO
0007E0 4D 50 54 00 54 4D 50 34 33 35 31 24 2E 54 4D 50 MPT.TMP4351$.TMP
0007F0 00 00 00 00 4C 49 43 45 4E 53 45 00 46 49 4E 49 ....LICENSE.FINI
000800 53 48 4D 53 47 00 00 00 69 33 38 36 00 00 00 00 SHMSG...i386....
000810 6D 69 70 73 00 00 00 00 61 6C 70 68 61 00 00 00 mips....alpha...
000820 70 70 63 00 56 45 52 43 48 45 43 4B 00 00 00 00 ppc.VERCHECK....
000830 49 4E 53 54 41 4E 43 45 43 48 45 43 4B 00 00 00 INSTANCECHECK...
000840 45 58 54 52 41 43 54 4F 50 54 00 00 54 49 54 4C EXTRACTOPT..TITL
000850 45 00 00 00 50 4F 53 54 52 55 4E 50 52 4F 47 52 E...POSTRUNPROGR
000860 41 4D 00 00 52 55 4E 50 52 4F 47 52 41 4D 00 00 AM..RUNPROGRAM..
000870 55 53 52 51 43 4D 44 00 41 44 4D 51 43 4D 44 00 USRQCMD.ADMQCMD.
000880 53 48 4F 57 57 49 4E 44 4F 57 00 00 52 45 42 4F SHOWWINDOW..REBO
000890 4F 54 00 00 6D 73 64 6F 77 6E 6C 64 2E 74 6D 70 OT..msdownld.tmp
0008A0 00 00 00 00 41 3A 5C 00 44 65 63 72 79 70 74 46 ....A:\.DecryptF
0008B0 69 6C 65 41 00 00 00 00 55 6E 68 61 6E 64 6C 65 ileA....Unhandle
0008C0 64 45 78 63 65 70 74 69 6F 6E 46 69 6C 74 65 72 dExceptionFilter
0008D0 00 00 00 00 6B 65 72 6E 65 6C 33 32 2E 64 6C 6C ....kernel32.dll
0008E0 00 00 00 00 43 6F 6E 74 72 6F 6C 20 50 61 6E 65 ....Control Pane
0008F0 6C 5C 44 65 73 6B 74 6F 70 5C 52 65 73 6F 75 72 l\Desktop\Resour
000900 63 65 4C 6F 63 61 6C 65 00 ceLocale.

this is something terrible bad (a bundle of viri installer)
http://www.virustotal.com/de/analisis/bbbbe6a2031667e6e53d9845cee43508
Be aware from installers in archives (zip, rar,...)!

some Av's don't detect it!!!

No comments:

Post a Comment