A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #20091  by TETYYSs
 Sat Jul 13, 2013 2:35 pm
Just found this in Lithuanian IT forum (http://www.itexposed.lt/t-fud-crypteris ... ?pid=34287)

http://anubis.iseclab.org/?action=resul ... ormat=html
---
File melted on startup. Then a happy startup key appeared in msconfig! Image Image
Image

Virus is already spreding, it was scanned in virustotal: https://www.virustotal.com/en/file/5dce ... /analysis/
Attachments
passwd:infected

Original file

(119.09 KiB) Downloaded 43 times
passwd:infected

Dropped file, which were in %appdata%\..\Local

(119.08 KiB) Downloaded 45 times