EP_X0FF wrote:This is BublikBublik/Bebloh
https://www.virustotal.com/file/f1be09d ... 337535273/
Can you change the topic title?
A forum for reverse engineering, OS internals and malware analysis
EP_X0FF wrote:This is BublikBublik/Bebloh
https://www.virustotal.com/file/f1be09d ... 337535273/
EP_X0FF wrote:For removal navigate toAdditional notes:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\userinit.exe
key "Debugger" will point to malicious file (in this case it was logonruser.exe). Delete key, reboot, delete dropper.
ReviewsAntivirus wrote:This is Bublik?Yes. Inject decrypted copy into csrss.exe.
https://www.virustotal.com/file/b165fd2 ... /analysis/