EP_X0FF wrote:That was actually worm Brontok, infected with Virut :)Yep. this is an infected file. I extracted virus code from this file. Virut infects PE file by using hooking technique and code injection technique. I use OllyDbg to load infected file and dump injected code from memory. I use the header of PE file from notepad.exe, remove all of unused sections. After attaching Virut code to the header, I can analyze it by IDA.
cured and unpacked in attach
https://www.virustotal.com/en/file/0cfe ... 368772119/
Virut code and IDB in attach :)
Attachments
password: infected
(74.88 KiB) Downloaded 86 times
(74.88 KiB) Downloaded 86 times