A forum for reverse engineering, OS internals and malware analysis 

All off-topic discussion goes here.
 #10396  by EP_X0FF
 Fri Dec 16, 2011 4:26 am
This file isn't working. It's crashes while decryption process.
 #10397  by rkhunter
 Fri Dec 16, 2011 5:03 am
EP_X0FF wrote:This file isn't working. It's crashes while decryption process.
You are correct. But why it was added? (~76.7%)
 #10398  by EP_X0FF
 Fri Dec 16, 2011 5:05 am
Because it has signs of obfuscation typical to malware + stupid copy-paste as always. Take Kaspersky detection and calculate count of fakeav.