Attachments
(638 KiB) Downloaded 94 times
A forum for reverse engineering, OS internals and malware analysis
markusg wrote:http://www.virustotal.com/file-scan/rep ... 1291740511Crypted with NET framework based cryptor.
\\.\Syser \\.\SyserDbgMsg \\.\SyserBoot \\.\SICE \\.\NTICEand VirtualBox, Sandboxie detection + a lot of others (if somebody interested all detection code placed at @0040B0F0, see attach from Meriadoc).
VBoxService.exe SbieDll.dllTopic title changed to malware name.
markusg wrote:http://www.virustotal.com/file-scan/rep ... 1291725015
Meriadoc wrote:Creates a directory C:\WINDOWS\system32\Windows (hidden+system)Didn't found any new winlogons in system.
file : winlogon.exe
opens backdoor
markusg wrote:http://www.virustotal.com/file-scan/rep ... 1291894474Yet the same.