A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #9748  by EP_X0FF
 Fri Nov 18, 2011 2:41 pm
International fake police alert ransoms discussion moved to dedicated topic
 #10856  by rkhunter
 Fri Jan 06, 2012 6:15 am
Another winlock, with aggressive behavior - Trojan:Win32/Ransom.EZ.

Makes impossible boot in safe mode - BSOD, because moves all services (from HKLM\System\CurrentControlSet\Control\SafeBoot) in special key - HKLM\System\CurrentControlSet\Control\SystemNls.

Runs from:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\system
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\iexplorer

Image
Attachments
pass:malware
(149.12 KiB) Downloaded 43 times
 #10912  by Xylitol
 Sun Jan 08, 2012 8:55 pm
found on blackhole
Code: Select all
95.57.120.135/files/71
Image

Also this dll payload also from bh
Image

and the last is NSFW.
Attachments
pw: infected
(516.72 KiB) Downloaded 50 times
pw: infected
(205.24 KiB) Downloaded 53 times
pw: infected
(214.2 KiB) Downloaded 50 times
  • 1
  • 5
  • 6
  • 7
  • 8
  • 9