A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #17176  by EP_X0FF
 Fri Dec 14, 2012 3:10 pm
Buster_BSA wrote:
Win32:Virut wrote:2 URLs, probably FakeAV
Code: Select all
hxxp://guchpaygoogles.info/data.exe
hxxp://monitorsupremenike.com/data.exe
Necurs maybe?
Yes, part of.
bcdedit.exe -set TESTSIGNING ON wb %s\drivers\%s.sys %x runas ComSpec \\.\NtSecureSys SeShutdownPrivilege kernel32 IsWow64Process rb Wow64DisableWow64FsRedirection Wow64RevertWow64FsRedirection *EUDC* ZwQuerySystemInformation ntdll.dll svchost.exe SystemDefaultEUDCFont EUDC\%d ObReferenceObjectByHandle ZwDuplicateToken ObOpenObjectByPointer PsReferencePrimaryToken PsInitialSystemProcess ObfReferenceObject IoGetCurrentProcess KeDelayExecutionThread
 #17616  by EP_X0FF
 Sat Jan 05, 2013 7:53 am
FakeAV/FakeAlert observed and collected in the 2012 year.

Please post any new samples in actual thread.

This thread now archived.
  • 1
  • 42
  • 43
  • 44
  • 45
  • 46