Windows XP Recovery
(also mentioned by Xylitol
here)
GUI
"Give me money" dialog
Probably also installs ZeroAccess, but dropper currently unavailable (has option "adw: download rootkit" and comes from site, which yesterday hosted ZAccess sample).
Muldrop, crypted then packed by UPX, payload it drops also crypted and packed by UPX. Uses IE injection. Dropper has AntiVM on board (VMWare, Virtual Box, Virtual PC).
In attach original dropper and extracted payload.
http://www.virustotal.com/file-scan/rep ... 1306508426