From 2013-02-24 to 2013-03-11 -- 72 items. Note the *_dler which appeared yesterday.
Attachments
Pass: infected
(4.84 MiB) Downloaded 144 times
(4.84 MiB) Downloaded 144 times
A forum for reverse engineering, OS internals and malware analysis
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\
HKU\Flexi\...\Run: [ctfmon.exe] C:\PROGRA~3\rundll32.exe C:\PROGRA~3\3jelori.dat,FG00 [x]
Startup: C:\Users\Flexi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\msconfig.lnk
ShortcutTarget: msconfig.lnk -> C:\PROGRA~3\3jelori.dat (No File)
Tcpip\..\Interfaces\{F359DE43-7CFB-41C3-8AD7-204DFFE88DFC}: [NameServer]0.0.0.0