A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #10320  by onthar
 Mon Dec 12, 2011 10:33 pm
Files unavailable =(
 #10691  by EP_X0FF
 Thu Dec 29, 2011 11:58 am
12048 unique droppers 1.03 GB, last one pack for 2011. Enjoy, pass malware.

200 mb, 1
http://www.megaupload.com/?d=H0WM1BNO

200 mb, 2
http://www.megaupload.com/?d=GCLEKX73

200 mb, 3
http://www.megaupload.com/?d=TYEE91I9

200 mb, 4
http://www.megaupload.com/?d=NU6RDVD2

9 mb, 5
http://www.megaupload.com/?d=J8VNXQ66
 #16323  by EP_X0FF
 Sat Oct 27, 2012 3:09 pm
Win32:Virut wrote:I'm not sure that this is Cidox.

3 samples attached.
Yes it is Cidox. Removal same - from AppInit_Dlls + cleanup of system32 folder.