A forum for reverse engineering, OS internals and malware analysis
EP_X0FF wrote:VT links posting are great, now attach the actual files or your post makes absolutely no sense.
http://forum.drweb.com/index.php?showtopic=324942started reversing, its does appear to read itself and...well.. there are AutoHotKey macros involved. :roll: would like to check out the file infector function, but im ok.
http://news.drweb.ru/show/?i=9999&lng=ru&c=5
tildedennis wrote: Comak (or anyone) know why the name "Bolek" ?I think because the guy who named is lacking imagination... ;]