Do you have any idea why the malware checks the ProductId of the victim system with 5 specified ProductId s???
Code: Select all
76487-640-1457236-23837 - Anubis 76487-640-1457236-23837 76487-644-3177037-23510 55274-640-2673064-23950 76497-640-6308873-23835 76487-640-1464517-23529 S b i e D l l . d l l s n x h k . d l l d b g h e l p . d l l VMware DiskVirtual_HD VBOX SOFTWARE\Microsoft\Windows NT\CurrentVersion ProductId SYSTEM\ControlSet001\Enum\IDE
76487-644-3177037-23510 - CWSandbox
55274-640-2673064-23950 - JoeBox
don't know from what last two
Anyway this never works with real AV lab.