markusg wrote:https://www.virustotal.com/file/42cc19b ... 348571320/Same as above. Difference in newly obfuscated dropper and rtk32 driver component. x64 backdoor the same.
Ring0 - the source of inspiration
A forum for reverse engineering, OS internals and malware analysis
markusg wrote:https://www.virustotal.com/file/42cc19b ... 348571320/Same as above. Difference in newly obfuscated dropper and rtk32 driver component. x64 backdoor the same.
markusg wrote:https://www.virustotal.com/file/42cc19b ... 348571320/This variant again :o
00:57:44.0713 1980 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys - copied to quarantine
00:57:45.0133 1980 C:\WINDOWS\$NtUninstallKB50933$\2002760106\@ - copied to quarantine
00:57:45.0133 1980 C:\WINDOWS\$NtUninstallKB50933$\2002760106\Desktop.ini - copied to quarantine
00:57:45.0133 1980 C:\WINDOWS\$NtUninstallKB50933$\2002760106\L\00000004.@ - copied to quarantine
00:57:45.0164 1980 C:\WINDOWS\$NtUninstallKB50933$\2002760106\L\uruzevfc - copied to quarantine
00:57:45.0164 1980 C:\WINDOWS\$NtUninstallKB50933$\2002760106\U\00000004.@ - copied to quarantine
00:57:45.0164 1980 C:\WINDOWS\$NtUninstallKB50933$\2002760106\U\00000008.@ - copied to quarantine
00:57:45.0164 1980 C:\WINDOWS\$NtUninstallKB50933$\2002760106\U\000000cb.@ - copied to quarantine
00:57:45.0164 1980 C:\WINDOWS\$NtUninstallKB50933$\2002760106\U\80000000.@ - copied to quarantine
00:57:45.0164 1980 C:\WINDOWS\$NtUninstallKB50933$\2002760106\U\80000032.@ - copied to quarantine
00:57:45.0604 1980 Backup copy found, using it..
00:57:45.0624 1980 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys - will be cured on reboot
00:57:45.0634 1980 C:\WINDOWS\$NtUninstallKB50933$\2002760106\@ - will be deleted on reboot
00:57:45.0634 1980 C:\WINDOWS\$NtUninstallKB50933$\2002760106\Desktop.ini - will be deleted on reboot
00:57:45.0634 1980 C:\WINDOWS\$NtUninstallKB50933$\2002760106\U\00000004.@ - will be deleted on reboot
00:57:45.0634 1980 C:\WINDOWS\$NtUninstallKB50933$\2002760106\U\00000008.@ - will be deleted on reboot
00:57:45.0634 1980 C:\WINDOWS\$NtUninstallKB50933$\2002760106\U\000000cb.@ - will be deleted on reboot
00:57:45.0634 1980 C:\WINDOWS\$NtUninstallKB50933$\2002760106\U\80000000.@ - will be deleted on reboot
00:57:45.0634 1980 C:\WINDOWS\$NtUninstallKB50933$\2002760106\U\80000032.@ - will be deleted on reboot
00:57:45.0634 1980 C:\WINDOWS\$NtUninstallKB50933$\946081224 - will be deleted on reboot
00:57:45.0634 1980 MRxSmb ( Virus.Win32.ZAccess.aml ) - User select action: Cure
lkd> !object \GLOBAL??
Object: e1005600 Type: (81fed5d0) Directory
ObjectHeader: e10055e8 (old version)
HandleCount: 1 PointerCount: 131
Directory Object: e1000298 Name: GLOBAL??
Hash Address Type Name
---- ------- ---- ----
81f18870 Device 0b765132
dumb110 wrote:anbody has this?? https://www.virustotal.com/file/6d32a06 ... 348810517/SHA256: 6d32a06be42f9c9b09038279d5121c8f9edd3fc3d5c670f3691d20d92dcddbff