rkhunter wrote:My post was about yoursEP_X0FF wrote: Well, you can find lots of different detections for sinowal for example. Alone itself it does not indicate anything. As I posted before I want to hear any updates from Erik, since he started this and probably he can share more info.Don't understand...post ago you told that them completely equal, you mean droppers or malicious VBRs? Or u mean various detections for both exactly equal boot-components? :?
guys all info here viewtopic.php?f=16&t=596&start=70#p15961Most of main code, I/O routines the same, reboot routine the same (just moved into separate procedure in new dropper) - everyone can verify this, I think even delay between reboot is the same.
Btw, currently I see that we haven't 100% facts, because these new droppers won't infect VBR.Lets start from the beginning. Under "infecting" VBR, what do you mean?
Ring0 - the source of inspiration