VT: https://www.virustotal.com/en/file/09bf ... 373050784/
SHA256: 09bfe80900b4efe99a7384d4594164386e9dabf2dbb3ce9cc05376172825b496
SHA1: 22a2fa170c50ef38d73e6cffa3bc1bdddfc1fda7
MD5: dd95e6e1d64b279fca51cf8f5f7abf36
I found this thing in friends PC, when he noticed that the desktop shows (like Win+D) out of nowhere when playing games, unusual behaviour for virus, but it was in his processes, then I found out that .js file was creating wSock.exe when ran with wscript.exe. Folder structure looks file firefox, but there's no firefox.exe, but wSock.exe instead, which has no valid digital signature (http://i.imgur.com/PvTjC1G.png). This folder was in C:\Program Files (x86)\Common Files.
SHA256: 09bfe80900b4efe99a7384d4594164386e9dabf2dbb3ce9cc05376172825b496
SHA1: 22a2fa170c50ef38d73e6cffa3bc1bdddfc1fda7
MD5: dd95e6e1d64b279fca51cf8f5f7abf36
I found this thing in friends PC, when he noticed that the desktop shows (like Win+D) out of nowhere when playing games, unusual behaviour for virus, but it was in his processes, then I found out that .js file was creating wSock.exe when ran with wscript.exe. Folder structure looks file firefox, but there's no firefox.exe, but wSock.exe instead, which has no valid digital signature (http://i.imgur.com/PvTjC1G.png). This folder was in C:\Program Files (x86)\Common Files.
Attachments
passwd:infected
(9.45 MiB) Downloaded 48 times
(9.45 MiB) Downloaded 48 times