C= Medhos ??
Ade Gill
Malwarebytes Researcher
Malwarebytes Researcher
A forum for reverse engineering, OS internals and malware analysis
Kafeine wrote:VT: 4608e9aae0491598c5b6a29703047360MS saying that detects new variant as Backdoor:Win32/Kelihos.F. This sample detected as TrojanDownloader:Win32/Waledac.C, moreover Kespersky detects it as Trojan-FakeAV.Win32.SmartFortress2012.ml...
(attached and also available here : http://minus.com/mi2Eq9H1A/ )
Related doc : Kelihos is dead. Long live Kelihos