Stupid KillAV.
It tries to kill some antivirus.
Strings
http://www.virustotal.com/file-scan/rep ... 1285460267
http://www.virustotal.com/file-scan/rep ... 1282089116
http://www.virustotal.com/file-scan/rep ... 1294498825
http://www.virustotal.com/file-scan/rep ... 1280846955
http://www.virustotal.com/file-scan/rep ... 1288712133
http://www.virustotal.com/file-scan/rep ... 1294491347
http://www.virustotal.com/file-scan/rep ... 1271858091
It tries to kill some antivirus.
Strings
drive (2).sys wrote:\\DosDevices\\xxxVirusTotal results
\\Device\\xxx
\\DosDevices\\xxx
\\Device\\HarddiskVolume1\\Arquivos de programas\\GbPlugin\\gbpsv.exe
\\Device\\HarddiskVolume1\\Arquivos de programas\\GbPlugin\\gbiehcef.dll
\\Device\\HarddiskVolume1\\Arquivos de programas\\GbPlugin\\gbieh.gmd
\\Device\\HarddiskVolume1\\Arquivos de programas\\GbPlugin\\cef.gpc
\\Device\\HarddiskVolume1\\Arquivos de programas\\GbPlugin\\gbieh.dll
\\Device\\HarddiskVolume1\\Arquivos de programas\\GbPlugin\\gbpdist.dll
\\Device\\HarddiskVolume1\\Arquivos de programas\\GbPlugin\\bb.gpc
\\Device\\HarddiskVolume1\\Arquivos de programas\\GbPlugin\\gbpkm.sys
\\Device\\HarddiskVolume1\\Arquivos de programas\\Scpad\\scpIBCfg.bin
\\Device\\HarddiskVolume1\\Arquivos de programas\\GbPlugin\\gbpsv.exe
\\Device\\HarddiskVolume1\\Arquivos de programas\\Scpad\\scpMIB.dll
\\Device\\HarddiskVolume1\\Arquivos de programas\\Scpad\\scpsssh2.dll
\\Device\\HarddiskVolume1\\Arquivos de programas\\Scpad\\sshib.dll
\\Device\\HarddiskVolume1\\Arquivos de programas\\Alwil Software\\Avast4\\ashLogV.exe
\\Device\\HarddiskVolume1\\Arquivos de programas\\Alwil Software\\Avast4\\VisthUpd.exe
\\Device\\HarddiskVolume1\\Arquivos de programas\\Alwil Software\\Avast4\\VisthUpd.exe
\\Device\\HarddiskVolume1\\Arquivos de programas\\Alwil Software\\Avast4\\ashWebSv.exe
\\Device\\HarddiskVolume1\\Arquivos de programas\\Alwil Software\\Avast4\\aswUpdSv.exe
\\Device\\HarddiskVolume1\\Arquivos de programas\\Alwil Software\\Avast4\\ashUpd.exe
\\Device\\HarddiskVolume1\\Arquivos de programas\\Avira\\AntiVir Desktop\\avscan.exe
\\Device\\HarddiskVolume1\\Arquivos de programas\\Avira\\AntiVir Desktop\\update.exe
\\Device\\HarddiskVolume1\\Arquivos de programas\\Avira\\AntiVir Desktop\\updfix.exe
\\Device\\HarddiskVolume1\\Arquivos de programas\\Avira\\AntiVir Desktop\\avupgsvc.exe
\\Device\\HarddiskVolume1\\WINDOWS\\system32\\scpsssh2.dll
\\Device\\HarddiskVolume1\\WINDOWS\\system32\\drivers\\gbpkm.sys
\\Device\\HarddiskVolume1\\WINDOWS\\Downloaded Program Files\\scpsssh2.inf
\\Device\\HarddiskVolume1\\WINDOWS\\Downloaded Program Files\\abn.gpc
\\Device\\HarddiskVolume1\\WINDOWS\\Downloaded Program Files\\erma.inf
\\Device\\HarddiskVolume1\\WINDOWS\\Downloaded Program Files\\gbieh.gmd
\\Device\\HarddiskVolume1\\WINDOWS\\Downloaded Program Files\\gbiehabn.dll
\\Device\\HarddiskVolume1\\WINDOWS\\Downloaded Program Files\\gbiehuni.dll
\\Device\\HarddiskVolume1\\WINDOWS\\Downloaded Program Files\\GbPluginABN.inf
\\Device\\HarddiskVolume1\\WINDOWS\\Downloaded Program Files\\GbPluginuni.inf
\\Device\\HarddiskVolume1\\WINDOWS\\Downloaded Program Files\\uni.gpc
String:%08X/n
String1:%08X/n
...
String33:%08X/n
c:\\dd\\objfre_wxp_x86\\i386\\ddr.pdb
IoDeleteSymbolicLink
RtlInitUnicodeString
IoCreateFile
IoFreeIrp
KeSetEvent
fDereferenceObject
WaitForSingleObject
fCallDriver
GetCurrentThread
KeInitializeEvent
IoAllocateIrp
IoGetRelatedDeviceObject
ObReferenceObjectByHandle
IoFileObjectType
ZwClose
DbgPrint
CreateSymbolicLink
http://www.virustotal.com/file-scan/rep ... 1285460267
http://www.virustotal.com/file-scan/rep ... 1282089116
http://www.virustotal.com/file-scan/rep ... 1294498825
http://www.virustotal.com/file-scan/rep ... 1280846955
http://www.virustotal.com/file-scan/rep ... 1288712133
http://www.virustotal.com/file-scan/rep ... 1294491347
http://www.virustotal.com/file-scan/rep ... 1271858091
Attachments
pass: infected
(18.83 KiB) Downloaded 153 times
(18.83 KiB) Downloaded 153 times